Modern attackers often do not need to install malware. They can phish a password, steal a session token, abuse a legitimate administrator tool, or use an overprivileged service account. NOV’s reported response was to make identity and application-level policy the main access boundary: the company says it reduced security incidents by about 35-fold, cut malware-related PC reimaging from roughly 100 machines a month to virtually zero, and governed access for approximately 27,500 users and third parties.
The figures come from NOV CIO Alex Philips in an April 18, 2025 VentureBeat interview. They are a valuable case study, not an independently audited benchmark or proof that one product stops every identity attack.
Why malware-free attacks put identity at the center
Traditional defenses were designed around a corporate boundary: firewalls separated the trusted office network from the internet, and a VPN often granted broad access after login. Cloud services, mobile work, SaaS, contractors and distributed operations have made network location a weak proxy for trust.
Malware-based intrusions leave a familiar artifact—a malicious file, executable or script. Malware-free, or “living-off-the-land,” intrusions instead use valid credentials, browser sessions, tokens, cloud APIs, remote-management software or built-in operating-system tools. “Malware-free” describes the absence of a conventional malicious payload, not a harmless or unsophisticated attack.
Recommended Free Tools
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
CrowdStrike’s 2025 Global Threat Report was cited by VentureBeat as finding that 79% of detections were malware-free. That is a CrowdStrike-reported detection statistic, with its own telemetry, definitions and measurement population. It should not be restated as “79% of all attacks.”
A typical identity-led attack path
- A target is phished, reuses a password, approves an MFA prompt, or loses a session cookie.
- The attacker authenticates successfully as a legitimate user.
- They use authorized browsers, scripts, remote tools or cloud APIs rather than dropping an obvious binary.
- Excessive group membership, a service account or a broad VPN route provides lateral access.
- Data is reached through SaaS, private applications or cloud services that endpoint signatures may not flag.
Identity therefore includes more than employees: contractors, privileged administrators, service accounts, machine identities, API tokens, certificates, workloads and emerging AI agents all represent identities that need ownership, authentication and authorization.
What “identity is the new perimeter” really means
The phrase is a prioritization principle, not a claim that networks, endpoints or data controls are obsolete. Identity is the control plane that can travel with a user, device, workload or service across cloud, private applications, remote locations and third-party relationships.
- Per-request authorization: evaluate each request instead of trusting a network once a user enters it.
- Contextual decisions: combine user, device posture, location, application, behavior and risk signals.
- Least privilege: grant only the application and actions required for a defined task.
- Continuous verification: step up, restrict or revoke access when conditions change.
- Application segmentation: limit paths between specific applications rather than relying only on large network zones.
TechTarget’s overview describes why IP address and physical network location have become less useful as primary trust signals in hybrid environments: identity is now a more consistent authorization boundary.
NOV’s reported starting point
NOV, described in the VentureBeat interview as a Fortune 500 oil-and-gas technology company, said it was operating with a traditional “castle-and-moat” model, substantial malware workload and dependence on physical security appliances. Philips reported approximately 100 malware-infected PCs being reimaged each month.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Those are NOV’s reported baseline conditions, not independently audited measurements. The April 18, 2025 VentureBeat interview does not establish the comparison period, the precise definition of a security event, whether the monitored population changed, or whether reporting thresholds changed during the program.
The architecture NOV says it adopted
Identity and conditional access
NOV put identity and conditional access at the center of policy. A request can be evaluated against the person or non-human identity, authentication strength, device health, location, requested application, role and current risk. The result may be approval, a step-up challenge, restricted access or denial.
Zero Trust private-application access
NOV reportedly used Zscaler’s Zero Trust Exchange, including policy-based access to thousands of internal applications for approximately 27,500 users and third parties. The applications were reportedly not directly exposed to the public internet.
Free tools Windows power users keep installed
One-click scans. No signup required.
Application-specific access can reduce broad VPN reach, constrain vendor permissions and make network location less important. It does not make an application immune to vulnerabilities, insider misuse, compromised credentials or authorized data theft; it reduces exposure and can narrow lateral paths.
Cloud-delivered enforcement
Philips characterized the cloud model as ending “appliance hell.” Potential benefits include centralized policy, less hardware maintenance, support for distributed users and less network backhauling. The trade-offs include provider availability, latency, egress, data sovereignty, integration effort, vendor concentration and the need for tested emergency access if the service is unavailable.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
What NOV reported achieving
| Metric | Reported result | What is established |
|---|---|---|
| Security incidents or events | Approximately 35-fold reduction | NOV CIO’s account; the baseline, period and counting method are not independently established in the April 18, 2025 VentureBeat interview. |
| Malware-related PC reimaging | Roughly 100 per month to virtually zero | Reported operational outcome; it does not prove malware disappeared. |
| Users and third parties | Approximately 27,500 | Reported population; whether this means active, entitled or all identities is not specified. |
| Internal applications | Thousands | Reported scale; an exact count was not supplied. |
| Internet exposure | Applications reportedly not directly exposed | Reduced public exposure, not a guarantee of security. |
All figures in the table are attributed to the April 18, 2025 VentureBeat interview. The most defensible interpretation is that NOV attributes the improvement to a broader transformation—identity protections, Zero Trust policy, cloud controls and security-operations changes—not to Zscaler alone.
How an identity policy can limit a stolen credential
Consider an explanatory model rather than a claim that every step is publicly documented for NOV:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match- A stolen credential passes the initial authentication check.
- Conditional access evaluates the device, location, application, user risk and authentication method.
- Phishing-resistant MFA or a step-up challenge is required when risk is high.
- The user receives access to an approved application, not an unrestricted network segment.
- Unusual downloads, privilege use or movement between applications generate correlated identity and endpoint signals.
- The account, session or entitlement can be revoked while the SOC investigates.
This approach cannot guarantee that credentials will not be stolen. It aims to make stolen credentials less useful and reduce the blast radius of an account that is abused.
The SOC and NOV’s generative-AI “co-worker”
NOV also described a generative-AI assistant for security operations. The April 18, 2025 VentureBeat interview does not specify whether it performs alert triage, query generation, case summaries, detection engineering, enrichment, playbook execution or threat-hunting assistance, so it should not be treated as an autonomous responder.
AI can accelerate investigation, but logs and artifacts may contain attacker-controlled prompt-injection content. Hallucinated conclusions, poor prioritization, sensitive-data exposure, excessive permissions, automation bias and model drift require controls.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
- Keep human approval for destructive or high-impact actions.
- Use narrowly scoped, auditable permissions.
- Record the inputs, recommendations and resulting actions.
- Validate important findings against source telemetry.
- Protect security data used for prompts, retrieval and model training.
What the case proves—and what it does not
Reasonable conclusions
- Identity and application policy address attack paths that do not depend on malware binaries.
- Replacing broad network access with specific application access can reduce exposure and lateral movement.
- Operational outcomes such as reimaging workload can improve when prevention occurs earlier in the access chain.
Claims the evidence does not establish
- The April 18, 2025 VentureBeat interview contains no independent audit of the 35-fold figure or the reimaging count.
- The figures do not show that Zscaler alone caused every improvement.
- Near-zero malware-related reimaging is not malware eradication.
- Lower event counts can reflect prevention, changed definitions, reduced visibility or environmental change.
- Zero Trust does not replace endpoint, network, application, data, physical or operational-technology security.
A practical adoption framework
- Inventory identities and applications. Include employees, contractors, service accounts, machines, tokens, certificates and privileged accounts; assign owners and business purpose.
- Strengthen authentication. Prioritize phishing-resistant MFA for administrators and high-risk access, and disable legacy authentication paths.
- Map authorization. Replace standing, broad privileges with role-based, application-specific and time-limited access.
- Integrate device signals. Distinguish managed, unmanaged, compromised and unknown devices before making access decisions.
- Reduce broad VPN reach. Publish private applications through explicit policies, while testing legacy protocols and industrial systems for compatibility.
- Control third parties. Provide narrow, auditable vendor access and revoke it immediately when contracts end.
- Correlate telemetry. Join IAM, endpoint, cloud, SaaS and network events so legitimate-tool abuse is visible.
- Add just-in-time privilege. Give engineers and responders temporary elevation instead of permanent administrator rights.
- Test resilience. Exercise identity-provider outages, break-glass accounts, low-connectivity sites and emergency operations.
- Measure exposure, not just alerts. Track privileged coverage, dormant accounts, exposed applications, high-risk sign-ins blocked, revocation time, attack-path reduction and recovery time.
Common failure modes
- Deploying phishable MFA and assuming authentication is solved.
- Leaving the directory, service accounts or delegated permissions overprivileged.
- Running access reviews as routine approvals rather than entitlement analysis.
- Removing a VPN without redesigning authorization.
- Applying policies that cannot support shared workstations, offline field sites or legacy applications.
- Granting an AI assistant excessive permissions or accepting its conclusions without validation.
- Failing to test break-glass access and provider-outage procedures.
Choosing the right control category
Products are not interchangeable. Start with the control gap:
| Primary gap | Relevant category | Examples |
|---|---|---|
| Broad private-network or VPN exposure | Zero Trust private-application access | Zscaler Private Access |
| Weak authentication and conditional policy | Identity provider and MFA | Microsoft Entra ID, Okta Workforce Identity, Cisco Duo |
| Abnormal use of valid accounts | Identity-threat detection | CrowdStrike Falcon Identity Protection |
| Excessive administrator privilege | Privileged-access management | CyberArk |
| Dormant, orphaned or uncertified entitlements | Identity governance and administration | Evaluate IGA capabilities separately from access brokering. |
Pricing, bundles and feature eligibility vary by geography, agreement and edition. The cited vendors generally use enterprise or plan-based pricing, so official pages—not an unverified list price—should guide procurement: Zscaler, Entra pricing, Okta pricing and Duo pricing.
Board-level measures that reflect real risk
Executives should ask how many critical applications are reachable through broad access, how many privileged accounts use phishing-resistant MFA, how quickly third-party access is revoked, how many service accounts lack owners, and how long recovery takes after identity compromise. A lower alert count is meaningful only when visibility, definitions and the monitored environment remain comparable.
The Bottom Line
NOV’s lesson is architectural rather than product-specific: make every access request explicit, contextual, limited and observable. Identity-centered Zero Trust can reduce the usefulness and blast radius of malware-free attacks, but it works only alongside resilient identity governance, endpoint and application security, data protection, network controls and disciplined security operations.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →




