{
"faqs":[
	{
	"category": "K7 InfiniShield",
	"question": "How does K7 InfiniShield gather data from various cybersecurity solutions without using hardware appliances?",
	"answer": "K7 InfiniShield uses host-based agents as collectors to capture event data. These agents can act as log aggregators and forward data flows and logs to K7 InfiniShield to monitor the cybersecurity solutions. A marketplace for sensors is available to facilitate integration with cybersecurity solutions from diverse vendors. With these technologies, K7 avoids the need for virtual machines or other hardware as collectors, significantly reducing investment and maintenance effort."
	},
	{
	"category": "K7 InfiniShield",
	"question": "How does K7 InfiniShield analyse behaviour?",
	"answer": "K7 InfiniShield leverages User and Entity Behaviour Analytics (UEBA) to identify anomalous behaviour. Logs from across the enterprise are aggregated and behavioural analysis is performed on both real-time and historical logs to establish patterns of normal behaviour specific to each organisation; deviations from such behaviour are identified and suspicious activities are flagged."
	},
	{
	"category": "K7 InfiniShield",
	"question": "Can cybersecurity be automated using K7 InfiniShield?",
	"answer": "Yes, K7 InfiniShield allows security teams to automate workflows and incident response. Security Orchestration, Automation, and Response (SOAR) enables capturing or deleting a malicious file, triggering password resets due to suspicious activity, and automated ticketing and email response. Playbooks are available, that can be used as-is or modified to suit the needs of each organisation, to perform pre-configured actions on the occurrence of specific events. Remediation measures can also be automated, such as logging off a user account that might be compromised or isolating an endpoint that might be infected."
	},
	{
	"category": "K7 InfiniShield",
	"question": "Will K7 InfiniShield help improve compliance?",
	"answer": "K7 InfiniShield helps improve compliance by offering a compliance dashboard that enables quickly ascertaining where IT systems are deviating from compliance requirements. Patch status is summarised to deliver an immediate update on whether all patches are installed or not, with automation of patching to mitigate vulnerabilities and drilldown to individual devices and tickets to understand obstacles to patching. Standards-specific compliance violations are listed, e.g., insufficient password length; descriptions of compliance requirements, such as password hygiene stipulations, provide compliance officers with an easy path to move towards compliance. Chief Information Officers (CIOs) can also easily obtain information on software used, to eliminate use of unauthorised or pirated software, and software publishers and device manufacturers, to avoid blacklisted vendors. "
	},
	{
	"category": "K7 InfiniShield",
	"question": "How does K7 InfiniShield help overcome an identified attack?",
	"answer": "Once an attack is determined to be ongoing, K7 InfiniShield’s Active Directory integration can reveal the complete attack path including an individual user’s access to service accounts. Security teams can obtain remote shell access on the affected machine from K7 InfiniShield’s console and suspicious files can be remotely extracted from the machine for analysis, avoiding the need for physical access. Mitigation measures, such as isolating the infected device or logging off a compromised user, can be automated."
	},
	{
	"category": "K7 InfiniShield",
	"question": "Does K7 InfiniShield work with custom applications and services developed for our specific requirements?",
	"answer": "K7 works with customers to integrate their bespoke services and applications with K7 InfiniShield through APIs. We also utilise APIs to determine response playbooks."
	},
	{
	"category": "K7 InfiniShield",
	"question": "How can my organisation leverage K7 InfiniShield’s powerful feature set without a full-fledged security team or SOC?",
	"answer": "K7 InfiniShield includes Managed Detection and Response (MDR) as a cybersecurity service where experts from K7 with multi-industry and multi-jurisdiction expertise perform remote cyberthreat analysis, detection, response, and remediation. 24/7 monitoring of the entire enterprise IT ecosystem, including endpoints, networks, applications, devices, processes, APIs, and cloud, backed by SLAs and KPIs, ensure proactive attack surface management. Customers save capex and opex as they don’t need to invest in building an in-house team or Security Operations Centre (SOC)."
	},
	{
	"category": "K7 Endpoint Security (K7 EPS)",
	"question": "Does K7 EPS depend on technology developed by K7 or by other companies?",
	"answer": "K7 EPS is entirely developed in-house by K7, including its scan engine. K7 is one of a few cybersecurity vendors in the world to have developed a proprietary scan engine. Developing a proprietary scan engine enables us to provide superior customer support as we can troubleshoot rapidly without depending on technology partners; our support team is also located in close proximity to the engineering team which permits greater collaboration. The proprietary scan engine also enables glitch-free solutions as we don’t need to integrate with 3rd party code, delivering stable upgrades that don’t crash or need a rollback."
	},
	{
	"category": "K7 Endpoint Security (K7 EPS)",
	"question": "K7 EPS is recognised for being light and fast. Why is that important?",
	"answer": "<p>K7’s scan engine, which is entirely developed by K7, has won many international awards and has been ranked World #1 in the performance test conducted by AV-Comparatives. Specifically, it is known for very low CPU and RAM utilisation which avoids the problem of cybersecurity slowing down devices and causing applications to crash. K7 has also developed a mechanism to deliver lean updates to K7 EPS and utilises add-on servers to distribute updates within a facility, ensuring cybersecurity does not choke the network; K7 has protected businesses operating in environments with just 24 kbps connectivity without impairing network performance.</p><p> K7’s light and fast technology ensures that customers do not need to invest in upgrading hardware, networks, or bandwidth, saving capex and opex. Productivity losses are also avoided as cybersecurity does not interfere with operations.</p>"
	},
	{
	"category": "K7 Endpoint Security (K7 EPS)",
	"question": "My organisation uses older devices running on platforms that are no longer supported, which makes them more vulnerable than other devices. Does K7 EPS secure such legacy systems?",
	"answer": "K7 EPS has wide platform support that includes out-of-the-box protection extending to Windows XP, ensuring that legacy devices enjoy protection against the latest cyberthreats. K7’s low-impact protection ensures that legacy devices, which may use older hardware with modest specifications, do not slow down due to cybersecurity."
	},
	{
	"category": "K7 Endpoint Security (K7 EPS)",
	"question": "What deployment models are offered with K7 EPS?",
	"answer": "<p>K7 EPS is offered with two deployment models: on-premises and cloud.</p> <p>K7 On-premises Endpoint Security includes a proprietary light weight web server which allow the console to be installed on any machine (endpoint or server) in the facility without requiring investment in, and maintenance of Apache, IIS, or any other server. The console can be accessed from any device in the network.</p> <p>K7 Cloud Endpoint Security has a console that is hosted in the cloud for anywhere, anytime access using just a web browser. It also supports 100% remote deployment. Individual endpoints do not need to be connected to the enterprise network to sync with the console, and can sync directly through public internet.</p>"
	},
	{
	"category": "K7 Endpoint Security (K7 EPS)",
	"question": "My organisation needs access to USB drives on some computers but not on others. Can USB access be controlled with K7 EPS?",
	"answer": "The Device Control feature in K7 EPS allows control over access to USB devices and other peripherals. Blocking based on Category, Device ID, and Class ID is supported. All computers that need access to USB drives can be included in a group that has a policy that permits access, and all computers that don’t need access can be included in a group that has a policy that blocks access."
	},
	{
	"category": "K7 Endpoint Security (K7 EPS)",
	"question": "I am concerned that unauthorised applications are being used in my organisation. Can K7 EPS help me control which applications can be used?",
	"answer": "The Application Control feature in K7 EPS can be used to control which applications are allowed to be used. Applications can be blocked based on version (to block outdated versions that may be vulnerable), file path, and MD5 value/checksum. Applications may also be allowed to run, but can be blocked from accessing the network or internet. Application use can be controlled based on user groups by creating policies for groups that block application access or specify the level of network access for an application."
	},
	{
	"category": "K7 Endpoint Security (K7 EPS)",
	"question": "Employees in my organisation need access to some websites, but allowing access to all websites impacts productivity and exposes us to many risks. Does K7 EPS allow selective access to websites?",
	"answer": "The Web Filtering feature in K7 EPS can be used to selectively block websites. Websites can be blocked individually or by category e.g., all social media websites can be blocked. K7 uses AI to automatically add websites to over 60 categories. An entire category can be blocked and exceptions can be created to allow access to individual websites. Websites can be blocked based on business hours and leisure hours. Organisations that use G Suite/Google Workspace can allow access to Google accounts linked to their domain but block access to personal Google accounts and G Suite accounts linked to any other domain."
	}
]
}