enterprisesecuritymag

Enterprise Security Magazine

Arete Incident Response
The Counterpunch to Cybercrime

Joe Mann, Founder & CEO, Arete Incident Response Joe Mann, Founder & CEO
Joe Mann is a recognized industry leader in information risk with over 20 years of experience servicing corporations, government agencies, and nonprofit organizations. Through his rich experience and expertise, Mann founded Arete Incident Response, a leading digital forensics and incident response (DFIR) company, as a one-stop solution to address the complexities in the cybercrime sector and to protect and defend organizations against the financial and reputational damages caused by data breaches. Having witnessed the acceleration of attack, from nation-state cyberattacks that shook the US industries in the early 2000s through highly sophisticated cybercrime attacks between 2015 and 2020, Arete has the experience and resources to address the current issues of the cybercrime industry. Mann remarks that the attacks have reached its pinnacle during the present time and denotes it as “the cybercrime tsunami.”

Arete, made of an elite team of cybersecurity experts with unparalleled capabilities to address the entire cyber incident life cycle, from incident response readiness assessments to post-incident remediation, provides services to its clients in three discrete service areas, namely response, remediate, and monitor. In the incident response phase, the company provides customized advice and a plan by its experts for the client, considering the issues from a legal perspective and understanding PII or PHI data. Arete also creates a proactive risk management strategy and services to improve their defensive and offensive cyber posture for the client.

In the remediation stage, the company conducts a complete analysis of different forensics and then helps the customer restore the corrupt or destroyed disk volumes or even entire disk environments from its back-up sources.

Arete further reinstalls and configures operating system, restores SQL servers and databases, installs new tools and technologies, and implements new group security rules to bring the organization to an operational state after a breach.

Our purpose is to create a real impact on society, delivering what is acquirable, sustainable, and in alignment to ethical integrity

In the final monitoring phase, the company partners with SentinelOne, a network security expert. It deploys managed a robust detection and response (MDR) platform that includes the US, Middle East, and Asia regions to automatically consume and operationalize a rich, curated set of dynamic threat intelligence. The company supplements the monitoring program with big data analytics and data warehouse, where every application that is funneled through is analyzed for its intelligence and enhancement.

Arete further demonstrates its excellence in the industry with the following client success story. A vendor partner to one of the insurance organizations approached Arete, as their systems were down, and they could not restore them. With a tremendous amount of time pressure and potentially significant impact on the business, Arete was able to get the organization back online within just one day, saving their business.

Arete is moving towards the future with a laser focus on becoming the counter punch to cybercrime globally. The company focuses on being agile, open to reengineering, learning, refining, tuning, and automating to achieve this end. With this approach, Arete is experiencing strong growth and becoming infinitely more scalable. Arete’s leaders are considered the ambassadors on global industry advancements, with regard to education and government initiatives from a regulatory, law enforcement, and industry perspective. In conclusion, Mann summarizes his company’s mission: “Our purpose is to create a real impact on society, delivering what is acquirable, sustainable, and in alignment to ethical integrity.”

Company
Arete Incident Response

Headquarters
New York, NY

Management
Joe Mann, Founder & CEO

Description
Arete Incident Response is a leading digital forensics and incident response (DFIR) company. It works as a one-stop solution to address the complexities in the cybercrime sector and to protect and defend organizations against the financial and reputational damages caused by data breaches. Arete, made of an elite team of cybersecurity experts with unparalleled capabilities to address the entire cyber incident life cycle, from incident response readiness assessments to post-incident remediation, provides services to its clients in three discrete service areas, namely response, remediate, and monitor. The company further focuses on being agile, open to reengineering, learning, refining, tuning, and automating to become the counterpunch of cybercrime

Arete Incident Response News

ARETE RELEASES TURNING TIDES - NAVIGATING THE EVOLVING WORLD OF CYBERCRIME DETAILING RANSOMWARE TRENDS AND SHIFTS IN THE CYBER THREAT LANDSCAPE

BOCA RATON - Arete, a leading global cyber risk management company, released Turning Tides – Navigating the Evolving World of Cybercrime, a report highlighting trends and shifts in the cyber threat landscape observed by Arete in the first half of 2023. The report leverages data collected during Arete incident response engagements and explores the rise and fall of ransomware variants, trends in ransom demands and payments, industries targeted by ransomware attacks, and what may be coming next.

Key findings within the report:

• During the first six months of 2023, LockBit emerged as the predominant ransomware strain, constituting 30.3% of the ransomware incidents recorded by Arete.

• The professional services sector continues to be the primary target, experiencing an uptick of nearly 12% compared to the latter half of 2022.

• Although the overall ransom demands by malicious actors are on an upward trajectory, Arete's data reveals that ransom payments were made in only 19% of cases during the initial half of 2023.

The provided report furnishes an extensive analysis of the five most prominent ransomware variants identified, along with comprehensive insights into initial access points and tools employed post-exploitation. The document further examines shifts within the threat landscape, encompassing the decreased barriers to entry in cybercriminal activities attributed to leaked resources, novel business models, and AI-powered tools. Additionally, it delves into the socioeconomic consequences of the Russia-Ukraine War and the rise in global law enforcement actions targeting cybercriminals.

"Cybercrime is constantly shifting in response to new vulnerabilities, developing technology, and global socioeconomic events," said Arete's Chief Data Officer, Chris Martenson. "Remaining aware of the latest trends and shifts allows organizations to take a proactive approach to cybersecurity and create data-driven strategies to protect their data and systems," Martenson added.

Kanguru Unveils Powerful New Remote Management Security Platform; KRMC-Hosted, With Enhanced UX for Managing Encrypted Storage Devices

MILLIS, Mass. -- Arete Incident Response Kanguru is proud to announce the launch of KRMC-Hosted, the latest upgrade to its renowned Remote Management Console (KRMC). This reimagined solution brings a sleek, modern interface and a suite of advanced features, elevating Kanguru's Data Storage remote management platform for Defender® secure, hardware-encrypted drives. The upgrade introduces a contemporary design, bolstered security measures, enhanced file auditing and reporting capabilities, and improved integration options, empowering organizations to deploy a more robust and seamless remote data security management system.

The KRMC-Hosted upgrade represents a significant leap forward in remote management security," says Matthew Buckley, Product Manager at Kanguru. "We've focused on enhancing user experience and expanding functionality to ensure our platform meets the highest standards of data protection and operational efficiency."

KRMC-Hosted allows organizations to efficiently manage a global fleet of AES 256-bit hardware-encrypted drives. Its new multi-tiered structure offers unparalleled flexibility and cost-effective security solutions for businesses of all sizes. KRMC-Hosted delivers comprehensive solutions that cater to diverse security requirements, certifications, and budget constraints, making it an ideal choice for maintaining robust data security.

Key enhancements in the KRMC-Hosted interface include:

Enhanced Security Actions

KRMC-Hosted introduces new security actions designed to protect against critical events:

Event-Based Ejects and Time Actions: This setting can automatically lock drives after a certain amount of time when a user logs out or the system enters sleep mode, based on parameters set by the Security Officer. This feature is particularly beneficial for Administrators managing drives used by contractors or temporary employees, ensuring data security within a defined time frame.

Application Launcher: Allows Administrators to include and manage executable files on company drives for streamlined business operations. Running applications on drive startup provides convenience and greater efficiency.

Group Control: Tailored security measures for users with higher requirements, such as enforcing stronger passwords for IT personnel or activating antivirus protection for Finance departments. Diverse needs met for any department or team without affecting the rest of the drives.

Advanced File Auditing and Reporting

Comprehensive Monitoring: Track file changes with detailed path reviews, receive separate event reports for larger file sizes and executables, and export drive file details for auditing.

Powerful Integrations

KRMC-Hosted now supports remote management of KRMC Authentication through SAML, OKTA, Azure, and Active Directory Federation Services. Active Directory integration enables automatic disabling of drives when a user account is deactivated, reducing the need to frantically locate remote USB devices and minimizing data theft risks. Additionally, SIEM connections provide IT-wide monitoring of KRMC events, ensuring thorough oversight. Administrators can configure these actions to occur within a specified timeframe, enhancing security and control.

Other enhancements include:

Streamlined Search Bar: Quick and intuitive access to devices, users, or actions.

Seamless Mobile Support: Fully integrated, user-friendly mobile experience.

Customizable Data Formats: Themed and personalized data views.

Flexible Sorting Preferences: Options for List or Bubble views, and Light/Dark themes.

Innovative Management Features: Enhanced control and oversight capabilities.

Looking ahead, Kanguru plans to further strengthen KRMC with upcoming integrations, including CI/CD (Continuous Integration/Continuous Deployment) policies, which automate and streamline the development, testing, and deployment of software. These policies are designed to enhance security measures for highly security-conscious organizations by ensuring faster and more reliable updates. Additionally, future updates will introduce internal device control alongside exceptional external device management, ensuring KRMC remains at the forefront of secure remote management solutions.

For more information about KRMC-Hosted, visit www.kanguru.com. For questions, contact the Kanguru Sales Team at 1-(508)-376-4245 or by email at sales@kanguru.com.

Kanguru is a global leader in delivering top-tier, secure data storage solutions, both external and internal, designed to help organizations protect and manage their critical information. Renowned for its industry-first remote management platform, Kanguru sets the standard for secure USB drive management. With over 30 years of expertise in providing intuitive, secure IT products, data duplication, and storage solutions, Kanguru is committed to meeting the evolving needs of modern businesses. For more information, visit www.kanguru.com.


© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.