<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content

Hypergate

ISEC7 × Hypergate

Acronis Cyber Files is ending and NTLM is on its way out: how Android and iOS stay connected

Acronis Cyber Files receives no security updates after 31 December 2026, and Microsoft is phasing out NTLM, the old Windows sign-in method. Both hit the same spot: how phones and tablets sign in to your own network and how they reach the file shares.

The replacement comes from Hypergate in Switzerland: Kerberos sign-in directly against the Active Directory you already run, and access to your existing file shares, with no cloud and no new server. ISEC7 rolls it out in your environment.

Request a free initial assessment

Webcast of 23 September: request the recording · Background in the blog post

Webcast with Hypergate · Recording

Recorded on

23

September 2026

Around 40 minutes, in German

Free on request

The Sovereign Mobile Workplace: watch the webcast

Simon Kolb of ISEC7 Group and Caglar Cölkusu and Lukas Schönbächler of Hypergate show how phones sign in to internal systems without the cloud and without NTLM.

  • Kerberos single sign-on on Android and iOS, directly against the domain controller
  • File access after Acronis Cyber Files: shares in the Files app, editing in Word, no new servers
  • Live demo, plus ISEC7 MAIL with Hypergate sign-in and the overview in ISEC7 SPHERE

Request the recording

What changes

In both cases something goes away that simply works today. Ideally, your staff won't notice.

Access to files

Many employees reach the file shares from their phone or tablet through Acronis Cyber Files. The product reached end of life on 31 December 2025; security updates continue until 31 December 2026.

The replacement is Hypergate Files. The app brings your existing Windows and NetApp shares straight into the Files app, with the permissions already set on them. No gateway, no extra server, no copy of the data on the device.

More about Hypergate Files →

Signing in

NTLM is an old Windows sign-in method. Microsoft is switching it off in stages: from October 2026 for NTLMv1, the oldest variant, and with the next major Windows Server release for the whole network. Microsoft describes the dates as tentative.

The replacement is Hypergate Authenticator. The app signs Android and iOS devices in via Kerberos directly at your domain controllers, with a certificate if you prefer. After that, the intranet and internal web apps open without another password prompt.

More about Hypergate Authenticator →

In-house apps and email

For Android apps you build yourself, there is the Hypergate SDK. With it, they too sign in via Kerberos instead of NTLM.

ISEC7 MAIL, our secure email app for iPhone, iPad and Android, already supports Hypergate as a sign-in method. So nothing changes for the mail app.

More about ISEC7 MAIL →

NTLM is under attack, not just out of date

In March 2025 attackers exploited a Windows flaw tracked as CVE-2025-24054, eight days after Microsoft had patched it. The main targets were government bodies and private institutions in Poland and Romania. Opening a folder that held a crafted file was enough, and Windows sent the NTLM hash to a server run by the attackers.

Source: Check Point Research, 2025

In brief

NTLM

Short for NT LAN Manager. An old Windows method a device uses to prove who it is. Microsoft is phasing it out.

Kerberos

A modern sign-in method. At sign-in the user receives a time-limited ticket and keeps working with it, instead of sending the password again and again.

SMB

The protocol that makes Windows and NetApp file shares reachable on the network.

Pass-the-Hash

An attack in which the attacker reuses a captured credential hash directly. They don't need to know the password itself.

How we go about it

Not every environment has to switch right away. Often the sensible first step is finding out where the old methods are still running at all.

Step 1

Inventory

We map where Acronis Cyber Files is in use and which devices and services still sign in via NTLM, with help from ISEC7 SPHERE. The initial assessment is free.

Step 2

Pilot with a test group

A test group receives the Hypergate apps through your existing UEM, for example Microsoft Intune, Ivanti or BlackBerry UEM. Hypergate provides the pilot free of charge for around 30 days, and you need no new servers for it.

Step 3

Switchover and operation

ISEC7 rolls out the solution while operations continue, and afterwards the Acronis servers are taken offline. On request, we run it for you as a managed service.

What you gain

No cloud, no new server

Sign-in and files stay in your own data centre. Hypergate talks directly to your domain controllers and file servers.

You see where you stand

ISEC7 SPHERE shows you which devices and services still use the old sign-in method before Microsoft switches it off.

One point of contact

ISEC7 looks after device management, the mail app and sign-in together, so you don't have to coordinate three projects in parallel.

Partner

Hypergate

Hypergate

Hypergate is a product of Papers AG, based in Zug, Switzerland. ISEC7 is a Hypergate partner for Germany, the United Kingdom and the United States. ISEC7 MAIL already supports Hypergate as a sign-in method, alongside smart cards and security keys such as YubiKey, AirID and CAC.

ISEC7 brings the implementation: we know your device management, check how everything fits with your mail environment, and take care of rollout and operation.

Visit Hypergate → · Blog post: Replacing Acronis Cyber Files and leaving NTLM →

Frequently asked questions

What replaces Acronis Cyber Files?

For mobile access to on-premises file servers there is Hypergate Files from Hypergate in Switzerland. The app brings your existing Windows and NetApp shares straight into the Files app on Android and iOS, with the permissions already set on them, without a gateway and without an extra server.

When does Acronis Cyber Files end?

Acronis Cyber Files reached end of life on 31 December 2025. Security updates continue until 31 December 2026.

What is Microsoft changing about NTLM?

Microsoft is switching NTLM off in stages: from October 2026 for NTLMv1, the oldest variant, and with the next major Windows Server release for the whole network. Microsoft describes the dates as tentative.

How do Android and iOS sign in without NTLM and without the cloud?

Hypergate Authenticator signs Android and iOS devices in via Kerberos directly at the domain controllers of your existing Active Directory, with a certificate if you prefer. After that, the intranet and internal web apps open without another password prompt.

What does ISEC7 do in the switchover?

ISEC7 maps where Acronis Cyber Files and NTLM are still in use, pilots the Hypergate apps with a test group through your existing UEM and rolls the solution out while operations continue. On request, ISEC7 runs it for you as a managed service.

Request an initial assessment or the recording

One sentence is enough: which solution do you use for mobile file access today, and would you like the webcast recording? We'll get back to you with an initial assessment and a suggested date. No obligation, and you don't need to prepare any documents.

Prefer to talk directly?

ISEC7 GmbH, Schellerdamm 16, 21079 Hamburg, Germany

sales@isec7.com · +49 40 325076 0