# Don’t let the promises of virtual desktop security cloud your judgement
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-12-12
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Securing Virtual Desktop Infrastructure: Risks &
Meta Description: Learn about the potential vulnerabilities of VDIs, such as trojans and malware, and how they can expose your organisation to cyber threats. Find out more here.
URL: https://financedigest.com/dont-let-the-promises-of-virtual-desktop-security-cloud-your-judgementhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1388013584-1736814730075-compressed.jpg)

_![Dave Waterson, CEO, SentryBay](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/683-1736814730114-compressed.jpg)_

_By **Dave Waterson,** CEO, SentryBay_

As banks, financial services companies and other large enterprises accelerate their digital transformation efforts, many are migrating workloads onto virtual desktop infrastructure. Among the myriad benefits are greater agility and efficiency and, if solutions are deployed in the right way, there are considerable financial savings to be made.

Organisations in the [sector regard their core competency to be in the provision of first-class financial](https://www.financedigest.com/tomorrows-world-how-cloud-computing-will-impact-the-financial-services-sector-in-2016.html "TOMORROW’S WORLD: HOW CLOUD COMPUTING WILL IMPACT THE FINANCIAL SERVICES SECTOR IN 2016") solutions and products. This is made easier if their [cloud-based desktop solutions](https://www.financedigest.com/vias-cloud-based-solutions-ensure-painless-office-move-for-insurance-body.html "VIA’S CLOUD-BASED SOLUTIONS ENSURE PAINLESS OFFICE MOVE FOR INSURANCE BODY") meet the needs of users across multiple departments and functions without it being necessary to configure devices if they are working remotely, or on the move, as well as in company offices.

While many of these solutions deliver elements of [security and privacy](https://www.financedigest.com/tesla-to-warn-of-data-privacy-risk-from-car-security-cameras-in-germany.html "Tesla to warn of data privacy risk from car security cameras in Germany"), and even the monitoring of access to virtual resources, they are not risk-free. More importantly, the supposed protection afforded by VDI can render users complacent, and this is making organisations vulnerable to cyberattacks. It is a misconception that an attack can’t be [launched on a virtual session without local](https://www.financedigest.com/danich-local-and-regional-banks-launch-mobile-wallet-powered-by-nets-new-hce-and-tokenisation-platform.html "DANICH LOCAL AND REGIONAL BANKS LAUNCH MOBILE WALLET POWERED BY NET’S NEW HCE AND TOKENISATION PLATFORM") storage, for example. In fact, VDIs provide multiple entry points to cloud servers, and all that a hacker needs, is one unprotected endpoint or device to make their way in.

**VDI vulnerabilities**

Virtualisation company VMware issued a security [advisory](https://www.darkreading.com/cloud/vmware-lpe-bug-cyberattackers-virtual-machine-data) earlier this year after discovering a vulnerability that allowed a bad actor with local non-administrative access to escalate privileges as a root user in a virtual machine. The company patched the issue. Meanwhile, vulnerabilities in Microsoft’s Azure Virtual Desktop (AVD) came to [light](https://techxplore.com/news/2021-08-microsoft-thousands-cloud-customers-vulnerability.html) in 2021 when a cybersecurity company was able to gain complete and unrestricted access to the accounts and databases of several thousand AVD customers. Again, the problem was fixed quickly.

Given the high incidence of data breaches – which according to [Statista](https://www.statista.com/statistics/1307426/number-of-data-breaches-worldwide/) exposed 15 million data records worldwide in the third quarter of 2022, a rise of 37% over the previous quarter – getting an understanding of the flaws and vulnerabilities in VDI security is crucial.

**The threats**

One of the main dangers comes from trojans and malware that steal keystrokes or take screen captures to gain the log-in details of users. They do this by looking for vulnerabilities in the devices that are connecting to applications such as Azure or VMWare, or even w365, one of the most commonly used [cloud PC subscription platforms](https://www.financedigest.com/solgari-releases-gdpr-mifid-ii-compliant-sms-service-as-part-of-integrated-omni-channel-cloud-communications-platform.html "Solgari releases GDPR & MiFID II Compliant SMS service as part of Integrated Omni-Channel Cloud Communications platform") available. The dangers are exacerbated by the number of organisations adopting Bring Your Own Device (BYOD) models, allowing employees to use their own laptops, tablets, [home PCs and smartphones to access corporate data](https://www.financedigest.com/simplifying-home-insurance-through-property-characteristics-data.html "Simplifying home insurance through property characteristics data") and applications. If these devices are unsecured, they present not only a threat to the user, but to all others they are working collaboratively with, the data that passes through their device and into the network, and risk non-compliance with the regulations that govern [financial services customer security](https://www.financedigest.com/what-can-we-learn-from-financial-services-security.html "What can we Learn from Financial Services Security?").

[Protecting users against spyware can be especially difficult when they are conducting video calls](https://www.financedigest.com/uk-opposition-calls-for-better-online-protections-for-children.html "UK opposition calls for better online protections for children") using Zoom or Teams, for example. Now so ubiquitously used, Teams has presented a new attack vector allowing [cyber criminals to deploy malicious GIFs to capture user data without even needing](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") to be shared – viewing the GIF is enough.

**The solution**

The question then, is what can be done to mitigate the risk so [financial services](https://www.financedigest.com/how-financial-services-are-overhauling-security-to-defend-against-spoofing-scams.html "How financial services are overhauling security to defend against spoofing scams") companies can fully embrace all the benefits of virtual desktop infrastructure? Of course, companies often opt to [manage their devices using anti-malware software](https://www.financedigest.com/reckon-software-goes-from-strength-to-strength-with-appointment-of-new-partner-development-manager.html "Reckon Software goes from strength to strength with appointment of new Partner Development Manager") and endpoint defence solutions, but these can fall down when it comes to enforcing their usage.  This is important because in a hybrid environment, it is a much greater [challenge for security](https://www.financedigest.com/the-challenge-of-keeping-data-secure-why-in-house-security-isnt-enough.html "The challenge of keeping data secure: why in-house security isn’t enough") managers to ensure protection is being deployed on remote endpoints.

The other difficulty is to find a [security solution that works with all the virtual applications](https://www.financedigest.com/application-security-in-the-finance-industry-what-you-should-know.html "Application Security in the Finance Industry: What You Should Know") and platforms that the organisation is using, and that they provide a level of protection that ensures regulations such as PCI-DSS, GDPR and HIPAA can be met.

Our advice is to assess enterprise-grade anti-keylogging and screen capture [protection for solutions](https://www.financedigest.com/aon-introduces-new-cyber-solution-in-response-to-eu-regulation-on-data-protection.html "Aon introduces new cyber solution in response to EU regulation on data protection") such as Azure Virtual Desktop and w365 at the endpoint. VDI sessions need to be secure from start to finish and include an enforcement agent to facilitate employee onboarding and [provide security managers](https://www.financedigest.com/newly-launched-quintessential-to-provide-prestige-living-management-platform-for-prs.html "Newly launched Quintessential to provide ‘prestige living’ management platform for PRS") with clear oversight regarding levels of engagement.

Organisations using VDI need [security solutions that create a container inside which all data](https://www.financedigest.com/2023-fintech-prediction-secure-and-private-data-usage-is-key.html "2023 FinTech Prediction: Secure and Private Data Usage is Key") and applications are wrapped so they cannot be infiltrated before they reach the cloud server. This not only provides an unprecedented level of protection to [financial services companies and banks but fits](https://www.financedigest.com/5-tips-for-financial-fitness-in-2021.html "5 tips for financial fitness in 2021") well into zero trust environments. And on top of this, the right solution will also preserve the fully enriched VDI-optimised Teams experience, making sure that video collaboration remains a [key touchpoint for the workforce](https://www.financedigest.com/6-keys-to-managing-a-remote-first-workforce.html "6 Keys to Managing a Remote-First Workforce").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

