Press Release

April 14, 2023 11:42 AM

Updated statement regarding LockBit claims

Mike Beck, Chief Information Security Officer, Darktrace

We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.

Press Release

April 13, 2023 9:30 AM

Statement regarding LockBit claims

Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.


Press Release

Darktrace Transforms Security Operations and Improves Cyber Resilience with Launch of Darktrace ActiveAI Security Platform™

Cambridge, UK
April 9, 2024
  • New innovations in Darktrace ActiveAI Security Platform provide more complete visibility across the enterprise to eliminate alert fatigue and illuminate security gaps freeing security teams’ to proactively improve cyber resilience.
  • Platform launches in an era of increasing AI-augmented threats, with new research finding that 74% of security professionals believe these threats are already having an impact, but 60% report their organization is unprepared.

Darktrace, a global leader in cybersecurity AI, today introduced the Darktrace ActiveAI Security Platform™. The platform includes Darktrace’s existing best-in-class security products supplemented by a set of new industry-first innovations and features, including for email and operational technology (OT). The platform uses AI to transform security operations from reactive to proactive and improve cyber resilience. To uplift human security analysts, the platform identifies weaknesses in security controls and processes before they are exploited, detects and responds to unknown, known, and novel threats, and automates the investigation of every alert to completion to reduce the manual triage process. Core to the platform is the ability to visualize, correlate, and investigate security incidents across cloud, email, network, endpoint, identity, and OT, as well as third-party tools and applications.

“At Capital Brands, we have a small team so maximizing our technology investments is crucial to ensure we are operating as efficiently and effectively as possible,” said Peter Huh, CIO & CTO, Capital Brands, which develops and sells domestic appliances with a focus on wellness nutrition to households in over 100 markets worldwide. “Darktrace’s platform acts as a force multiplier for us, allowing our team to move away from the purely reactive nature of cybersecurity – which often leaves security teams one step behind – to a more proactive state. We gain a deep understanding of our environment that helps us prioritize in a way we haven’t been able to in the past. We can automatically identify vulnerabilities so we can quickly remediate the things that matter and deprioritize the things that don’t.”
“Security teams are reaching a breaking point, forced into a reactive state by too many alerts, too little time, and a fragmented security stack,” said Max Heinemeyer, Chief Product Officer, Darktrace. “Building on a decade of experience applying AI to transform security operations for thousands of customers, the Darktrace ActiveAI Security Platform takes a unique approach from the rest of the industry. It correlates incidents across the digital environment and automates investigations to uplift security teams and free them from the manual, time-intensive alert triage process so they can focus their time on building proactive cyber resilience.”

New Report Finds Lack of Cyber Preparedness in an AI-Threatened World

AI is beginning to amplify the already complex threats faced by cyber security professionals. The rise of offensive AI combined with automation and cybercrime-as-a-service is increasing the speed, sophistication, and success of cyber security attacks. Multi-stage and multi-domain attacks are now widely used by adversaries, who take advantage of a lack of visibility and siloes to move undetected between systems.

A new Darktrace-commissioned report released today underscores the challenges facing businesses in this rapidly evolving cyber-threat landscape. Darktrace’s State of AI Cybersecurity 2024 report, which surveyed nearly 1,800 security leaders and practitioners in 14 countries, found 74 percent of respondents believe AI-augmented cyber threats are already having a significant impact on their organizations, yet 60 percent believe they are currently unprepared to defend against these attacks. The AI Cybersecurity report also found:

  • Organizations face two top inhibitors to defending against AI-augmented threats: insufficient knowledge or use of AI-driven countermeasures[1] and insufficient personnel to manage tools and alerts[2].
  • Security professionals surveyed believe defensive AI will effectively counter offensive AI, with 71 percent of respondents indicating they are confident that AI-augmented security solutions will be able to detect and block AI-augmented threats. However, only 26 percent fully understand which types of AI are used in their security stack today.
  • As they prepare for these threats, security teams want to consolidate their tools. 85 percent of those surveyed agreed that a platform approach is more effective at stopping threats.

Introducing the Darktrace ActiveAI Security Platform

Against this backdrop, Darktrace is introducing the Darktrace ActiveAI Security Platform to help organizations transform their security operations from a focus on reactive threat detection to proactive cyber resilience. The platform includes Darktrace’s core detection and autonomous response capabilities with pre-breach prevention, attack simulation and recovery capabilities in a single, holistic solution with a common AI architecture. The platform enables teams to visualize and correlate events across a broad set of domains including cloud, email, endpoint, identity, network, and OT environments.

The platform is built on Darktrace’s Self-Learning AI engine, which directly applies multiple types of Al to the data of each business so that it can continuously learn from its unique digital environment to understand what is normal and what is not. Darktrace’s AI detects known, unknown, and novel threats in real-time and provides an autonomous response that contains active threats without disrupting business operations.

New features and innovations unveiled today in the Darktrace ActiveAI Security Platform include:

  • More explainable, automated, and customizable investigations for all alerts: Darktrace Cyber AI Analyst™ will now reveal the results of its investigations for every security alert, rather than just those escalated to an incident. This helps security analysts understand how the AI reached its conclusion that escalation wasn’t required. Cyber AI Analyst also can now be customized to perform investigations that are tailored to each business’s unique needs. For example, it can investigate activity surrounding a threat intelligence finding from a 3rd party alert for evidence of a cyber incident or investigate activity surrounding violations of a company-specific compliance policy for evidence of an insider threat. Cyber AI Analyst was first introduced in 2019 and uses AI trained to mirror how human security analysts conduct investigations. Unique in the industry, it automatically investigates every alert to completion and identifies precise response actions that can be taken autonomously to contain threats. Rather than security teams triaging a small portion of alerts, Cyber AI Analyst triages all of them. This helps to reduce alert fatigue and free up time for security teams, who can instead focus on proactively hardening their security controls and refining incident handling procedures.
  • Decryption: The platform will include new integrations with third-party network solutions to provide decrypted traffic feeds and decryption keys. It will also include native decryption for Microsoft Windows and Apple Mac applications, including internet browsers.
  • New Firewall Rule Analysis to Pre-empt Threats: Darktrace PREVENT/End-to-End™, which provides pre-breach preparation, now includes the ability to analyze firewall rules, allowing it to provide a more comprehensive view of potential unauthorized traversal points or attack paths within IT, OT or in between, identifying risks in configuration and pre-empt threats.
Darktrace Cyber AI Analyst™ now reveals the results of its investigation for every security alert to help security analysts understand how the AI reached its conclusion and why it took specific actions. Cyber AI Analyst can visualize, correlate, and investigate security incidents across all areas of the digital environment as well as from third party tools.

Additionally, Darktrace will release enhancements to its best-in-class email and OT security solutions, which can be purchased as stand-alone products based on each organization’s unique project needs.

Darktrace/Email™ will include new features that use AI to stop early-stage phishing, spot early symptoms of account compromise across a broader range of communications and increase SOC efficiency. The new email features include:

  • New data loss prevention capabilities that use AI to detect abnormal user behavior and changes to content beyond those offered by native email providers, helping teams identify the full spectrum of accidental and malicious data loss.
  • Coverage for Microsoft Teams to detect and stop novel, insider, and sophisticated early phishing threats often missed by other solutions, especially when communications span both collaboration and email tools.  
  • New Darktrace/DMARC creates an easy way to help protect an organization’s brand with an industry first AI-assisted deployment of the Domain-based Message Authentication (DMARC) email authentication protocol to continuously stop others spoofing and phishing from a business’s domain names.
  • More robust account takeover protection that can now prevent lateral mail compromise with an addition to our AI behavioral profile for each user that spots early symptoms of account compromise and malicious insiders before a link or attachment payload is sent and exfiltration occurs.  
  • New Mailbox Security Assistant feature helps to reduce reporting of potential false positives by 60 percent[3], which can help the security team save time on analysis. The feature provides end-users with a natural language summary and context of why an email may be malicious. This helps improve their knowledge and decrease the risk of successful phishing attempts.
  • New behavioral link analysis capabilities that can reveal hidden intent within interactive and dynamic webpages to help users and security teams detect more sophisticated malicious phishing links.
The new Mailbox Security Assistant feature in Darktrace/Email™ uses AI to provide end users real-time contextual feedback of each reported email. This helps to upskill end-users and reduces the time security teams spend analyzing end-user reports of false positives. This image shows a user analyzed email that would be reported to the security team for continued re-evaluation and learning.  
This image shows the same email from the perspective of a security professional after it has been analyzed and reported by an end-user using the new Mailbox Security Assistant feature in Darktrace/Email™.

Darktrace/OT™ will include new capabilities that go beyond traditional Common Vulnerability and Exposure (CVE) scoring to help organizations identify, prioritize, mitigate, and continuously review the risks and potential attack paths that are specific to their OT infrastructure. In addition to identifying and prioritizing risks more effectively, Darktrace/OT can now evaluate each business’s defenses against the tactics of Advanced Persistent Threat (APT) Groups. Darktrace/OT maps MITRE techniques and known threat groups tools, tactics, and procedures (TTPs) against unique attack paths identified within the business.

Availability

New features in the Darktrace ActiveAI Security Platform are expected to be available in early calendar Q2 2024.

Additional Resources

ABOUT DARKTRACE

Darktrace (DARK.L), a global leader in cybersecurity artificial intelligence, is on a mission to free the world from cyber disruption. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 175 patent applications filed. Rather than study historic attacks, Darktrace's technology continuously learns and updates its knowledge of your business data and applies that understanding to help transform security operations to a state of proactive cyber resilience. The Darktrace ActiveAI Security Platform™ provides a full lifecycle approach to cyber resilience that can autonomously spot and respond to known and unknown in progress threats within seconds across the entire organization, including cloud, apps, email, endpoint, network and operational technology (OT). Darktrace, which listed on the London Stock Exchange in 2021, employs over 2,300 people around the world and protects over 9,200 customers globally from advanced cyber threats. To learn more, visit https://darktrace.com/.

[1] Rated 3.36 by respondents on a scale of 1 (not at all) to 5 (extensively).

[2] Rated 3.35 by respondents on a scale of 1 (not at all) to 5 (extensively).

[3] Based on internal Darktrace testing in February and March 2024, which evaluated the number of analyzed versus reported emails for users with the feature.

News coverage
News publication logo

Darktrace Transforms Security Operations and Improves Cyber Resilience with Launch of Darktrace ActiveAI Security Platform™

April 9, 2024

cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms ·      Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP.  We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1]  19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account     take over and Lateral mail account compromise protection.     Contributing yet another layer to the AI behavioural profile for each     user, security teams can now spot early symptoms of account compromise or     malicious insiders before a link or attachment payload is sent, and     exfiltration occur   Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to     behavioral and natural language content analysis that tracks context     across both email and instant messaging to identify the approximately 38% of     phishing, sophisticated social engineering and novel insider threats other     solutions fail to capture ·      Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.·       MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.·       AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections.   Download the fullMagic Quadrant for Email Security Platforms here Resources:·      Read more onthe Darktrace Blog·      Read more abouthow business email compromise attacks are evolving on The Inference  Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose.  About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com.   ---- 
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'