Home Blog Page 178

Financial Regulator FINRA Alerts About Ongoing Phishing Campaign via Fake Sites

phishing campaign, Smishing attacks

The U.S. Financial Industry Regulatory Authority (FINRA) warned about threat actors targeting users with spoofed websites and domains to steal sensitive information. Attackers are using FINRA members’ real names and images to trick users into believing that they are legitimate.

FINRA regulates member brokerage firms and exchange markets. In a security alert, the agency stated that the phishing attacks via fake websites are on rise. This is because attackers are using registered brokers’ data to create phishing emails and imposter websites. The fake emails are embedded with phishing links or malicious attachments that contain malware. Several members fell victim to these sites, compromising their personally identifiable information (PII) like names, email addresses, and contact details.

Several firms have recently informed FINRA that malicious actors are using registered representatives’ names and other information to establish websites that appear to be the representatives’ personal sites, and are also calling and directing potential customers to use these imposter websites. Imposters may be using these sites to collect personal information from potential customers with the likely end goal of committing financial fraud.     

                                                                                                 

                                                                                                          –  FINRA 

Trace the Phish

The imposter domains used in this phishing campaign include common features like:

  • Using the registered representative’s name as the domain name for the website as in firstnamemiddlenamelastname.com.
  • Including a picture purporting to be the registered representative.
  • Providing information about the registered representative’s employment history, including prior employers’ CRD numbers and examination history.
  • Asking individuals to fill out a contact form with the individuals’ names, email addresses, phone numbers, the subject of the inquiry and space for a message.

FIRNA stated that the imposter websites contain poor grammar, misspellings, odd or awkward phrasings, or misuse financial services terminology. It advised member firms and registered representatives to follow necessary security actions to identify such phishing webpages and emails.

Homoglyph Phishing Attacks

Security experts from Malwarebytes discovered cybercriminals using a combination of fake domains with favicons to launch “Homoglyph Attacks.” The attackers used Homoglyph attack — also known as homograph attack, script spoofing, or homograph domain name spoofing — in phishing scams, credit card skimming attacks, and on several domain names to load the inter skimming kit inside of a favicon, a file containing one or more small icons associated with a particular website.

Cybersecurity Start-Up Funding Surged by 940% in the U.K.

Startup funding

A new research from recruitment firm Robert Walters revealed that the cybersecurity sector has been witnessing a significant growth during the ongoing pandemic. The research report “Cybersecurity Building Business Resilience” highlighted that the funding for the cybersecurity startups in the U.K. has surged by 940% during the period. In total, investors raised over £496 million (US$ 650.139 million) in the first half of 2020. In fact, a new cybersecurity business is registered every week on average, with a 44% rise in organizations providing cybersecurity products and services, according to the research.

“While a challenging economic climate has compelled firms to rationalize areas of their business, the data-centricity of operations has cemented the importance of an infallible cybersecurity strategy in a new era of work. Against the backdrop of remote working and the rise of COVID-19 related IT security attacks, those investing in their cybersecurity function are proving to be the organizations that can ensure business continuity and take a proactive stance against emerging threats,” the report said.

Key Highlights:

  • There is a talent shortage of 140,000 cybersecurity professionals across Europe.
  • 70% of companies in Europe do not have a sufficient cybersecurity team.
  • Only 1000 firms in the U.K. provide cybersecurity services.
  • 1 in 3 employers state that cybersecurity professionals will be in demand post COVID-19.
  • While SIEM (50%) and ethical hacking (30%) are emerging skills required to implement a robust cybersecurity strategy, less than 1% of U.K. technology professionals possess these skills.

Demand for Cybersecurity Talent

According to the research, a third of organizations stated that cybersecurity professionals will be in demand post-COVID19 outbreak, while 25% of businesses highlighted the need for cloud computing skills. Despite COVID-19, the vacancies for cybersecurity professionals in 2020 are in high demand. While vacancies for IT professionals have declined by -40%, the cybersecurity volumes have increased by +5.5% in H1 2020 in comparison to the same period last year. January 2020 witnessed a surge in recruitment of cybersecurity professionals, wherein the total number of vacancies was over double the 2019 monthly average, at +38%.

Ajay Hayre, Senior Consultant Technology, Robert Walters, commented, “As businesses continue to invest in cybersecurity software and adopt new platforms, there will be a heavy emphasis on Cloud skills, security engineering and site reliability engineering. Professionals involved in security orchestration with strong SIEM skills such as Splunk will be highly valuable, as well as AWS container security and micro service security architecture. Businesses will have to make heady attempts to secure cybersecurity specialists, where possible tapping into passive candidate markets to secure the best talent.”

Freepik Suffers Data Breach, 8.3 Mn Users Affected

credential phishing campaigns

Free photos and graphics platform, Freepik has admitted it became a victim of a major security breach which may have affected over 8.3 million users. In a security alert, the company stated that hackers unauthorizedly obtained emails and hashed passwords of its Freepik and Flaticon website users.

Attack via SQL Injection

The data leak occurred after attackers exploited an SQL injection vulnerability to gain access to one of its databases that held users’ data.

“We determined that an attacker extracted the email and, when available, the hash of the password of the oldest 8.3M users,” Freepik said in a statement. The company also clarified that the obtained hash of the passwords are not actual passwords and cannot be used to log into user accounts.

According to Freepik, of 8.3 million users, 4.5 million had no hashed password as they used combined logins (with Google, Facebook and/or Twitter), and the only data the attackers may have obtained from them was their email address. The rest of the 3.77 million users had their email addresses and passwords compromised. “For 3.55M of these users, the method to hash the password is bcrypt, and for the remaining 229K users the method was salted MD5. Since then we have updated the hash of all users to bcrypt,” the statement added.

Notifying the Affected

The company has reported the breach incident to the authorities and are notifying the affected users. “Those who had a password hashed with salted MD5 got their password canceled and have received an email to urge them to choose a new password and to change their password if it was shared with any other site (a practice that is strongly discouraged). Users who got their password hashed with bcrypt received an email suggesting them to change their password, especially if it was an easy to guess password. Users who only had their email leaked were notified, but no special action is required from them,” Freepik added.

Four Biggest GDPR Fines of 2020

GDPR fines in 2020

Marriott International encountered a London class action from millions of its former guests claiming compensation after their personal information was compromised in a massive data breach between 2014 and 2018. However, this was not the first time for the popular hospitality firm to face a lawsuit. In July 2019, the U.K.’s Information Commissioner’s Office (ICO) imposed a £99.2 million (US$123.7 million) fine on Marriott failing to protect its customers’ information and violating the EU’s General Data Protection Regulation (GDPR) regulations.

By Rudra Srinivas, Feature Writer, CISO MAG

As per the GDPR guidelines, organizations are accountable for the customers’ personal data they hold. Ever since the GDPR was launched (on May 25, 2018), the data regulators have churned out high penalties from organizations for data breaches and misuse of customer information.

The year 2019 had already seen several organizations slammed with sizable fines and settlements for security incidents. Here is a glimpse at the organizations that suffered the biggest GDPR fines in 2020 so far:

1. Google

In January 2019, Google was fined 50 million euros (around US$57 million) by the French data regulator CNIL (National Data Protection Commission) for violating the GDPR norms. The fine was levied for Google’s limited information, lack of transparency, and valid consent from its users regarding ads personalization.

Google’s fine is from the last year, and the search engine giant challenged the verdict. In June 2020, the Council of State in France rejected the appeal and upheld the penalty.

Google also agreed to pay $7.5 million in a settlement to resolve a class-action lawsuit filed with the U.S. District Court Judge Edward Davila in San Jose for exposing the private data of around 500,000 former Google+ users to third-party developers.

2. TIM

In January 2020, the Italian Data Protection Authority (Garante) imposed a €27.8 million (US$31.5 million) fine on telecommunications operator TIM for violation of the GDPR guidelines. The company got sued for its unauthorized data processing activities, aggressive marketing strategy, data breaches, and illegal collection of consents.  Millions of users were flooded with promotional calls and unsolicited communications, including non-customers and members in exclusion lists.

3. Wind Tre S.p.A.

In July 2020, Garante fined over €16.7 million (US$ 21.8675 million) on Wind Tre, a mobile telecoms operator, for using customers’ personal data without their consent. The company was also accused of aggressive direct marketing techniques that violated the GDPR regulations.

4. Unknown Firm in Netherlands

In April 2020, the Dutch Data Protection Authority imposed its largest fine €725,000 (US$ 821,600 million) to date to an unknown company for illegally using employees’ fingerprint scans for its attendance records over the period of 10 months. As per the GDPR, biometric data is classified as sensitive information and subjected to stringent protections.

These GDPR fines should act as an eye-opener to other organizations that are not abiding by the data security policies.  Apart from financial implications, a GDPR fine could also affect the organization’s image and even lead to permanent loss of customers. Therefore, it is worthwhile for organizations to consider the legal requirements of the GDPR.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

FBI and CISA Issue a Lookout for Vishing Attacks

vishing attacks

The U.S. law enforcement bodies, the Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA), have in a joint advisory warned of a new attack/scam vector being used to target the remote workforce. Known as phone phishing or vishing, these vectors have surfaced mid-July and have been targeting corporate employees to gain access to their company’s internal systems.

How Does a Vishing Attack Work?

Vishing attack is a combination of “voice” and “phishing.” Vishers generally make use of an internet telephone service like Voice-over-Internet Protocol (VoIP) for impersonating a person or legitimate business to scam people. Attackers use social engineering techniques to trick people into giving up their information. They also create fake Caller ID profiles (called Caller ID spoofing) to make any phone number look legitimate. The only goal of a vishing attack is to steal the victims’ money and/or identity.

The Modus Operandi

  • The cybercriminals first registered phishing domains identical to the targeted company’s resources, for example, their internal VPN login page, and then created phishing portals on these domains. To add a flavor of authenticity, the malpractitioners also added two-factor authentication (2FA) and/or one-time passwords (OTP), if present. Some of the most common naming schemes used were: support-[company], ticket-[company], employee-[company], [company]-support, [company]-okta
  • Cybercriminals then compiled a database of all the employees working for the target companies by scraping through their public profiles on social media platforms, recruiter tools, background check services through public forums, and open-source research.
  • They collected employee information which included name, home address, personal cell/phone number, the position at the company, and duration at the company.
  • Once the research was thorough and complete, the cybercriminals tele-called the employees using random Voice-over-Internet Protocol (VoIP) to fool them. At a later stage, they even began spoofing the phone numbers of other employees to win over their victims’ trust.
  • In certain instances, it was observed that the cybercriminals used social engineering techniques such as impersonating themselves as the company’s IT help desk. They used the PII of the employees obtained from various platforms to make them believe about their identity and once trusted they asked them to send the 2FA or OTP validation received for a VPN credential reset.
  • Additionally, they also used a sim-swapping or sim jacking technique on the targeted employees to obtain the 2FA or OTP credentials.
  • On gaining internal system access, the criminals then searched the mainframe computer for valuable and confidential information which could be stolen for monetary benefits.

Mitigation Steps

These types of vishing attacks previously were known to primarily target the telecommunication sector, however, it is now spreading like wildfire because of the distributed and remote workforce. Thus, to avoid these vishing attacks, the following can be done:

  • Allow VPN access only to managed devices.
  • If possible, restrict VPN access hours.
  • Keep an eye on fake domain names similar to your company’s domain(s).
  • Implement the least privilege access principle to avoid unwanted access.
  • Implement an employee-to-employee secondary verification mechanism while communicating over the public telephone or cellular line.

U.S. Military Personnel Lost $379 Mn to Fraudulent Schemes in Last 5 Years

U.S. Military Personnel and Veterans

An investigation from AtlasVPN revealed that the U.S Military personnel have lost around $379.6 million to a range of fraudulent schemes from 2015 to June 30, 2020. According to the report, military staff have reported more than 680,000 complaints about fraud, identity theft, or other consumer issues to the Federal Trade Commission (FTC).

These complaints were categorized into three different types:

  • Complaints from all military members including reserved forces & their family members
  • Complaints from currently active members
  • Veterans & retired personnel

Key highlights from the analysis include:

  • Most Military Personnel lost around $51.9 million in damages to fraud schemes like lottery scams, with 10,822 people reported being a victim of lottery or similar scams.
  • Over 22.4% of people who reported scams did lose money, with a gross average loss of $2,800.
  • Veterans & retired personnel accounted for over 417,560 complaints and lost over $217.2 million
  • The monetary damages to military personnel was at $46.5 million. Government impersonation scam was reported the most, with 112,987 complaints since 2015.
  • Impersonating businesses caused $36.6 million in monetary damages since 2015, with 31,334 people cases of fraud where impostors pretended to be high-profile businesses.
  • Romance scams lured out $24.5 million from unsuspecting victims, with 1,666 people becoming victims to the scams. Around 56.2% claimed that they lost money to these scams.
  • Online Shopping scams cost $11.3 million, with personnel raising a total of 13,935 complaints, with 65.6% of them reporting financial damages. The median loss for online shopping scams was the lowest at $166.
  • Consumers reported investment seminars and investment advice scams 100 times since 2015, but the median loss was at $20,000. With only 100 complaints, this scam lured out a total of $2.3 million.

“Veterans were behind the lion’s share of the losses. The veterans & military retirees’ monetary damages encompass 57% of all losses, totaling $217.2 million. Veterans and retirees sent out 417,560 complaints. In other words, 61% of complaints in the last 5 years have been sent by veterans and military retirees,” the report stressed.

Hackers Target U.S. Veterans

Security researchers from Cisco Talos discovered a threat group targeting U.S. military veterans via a fake job portal promising help for those looking for jobs. Hacker group, named Tortoiseshell, have been targeting Americans who are in search of jobs, especially military veterans via a phony hxxp://hiremilitaryheroes[.]com, like the legitimate one https://www.hiringourheroes.org, to trick U.S. military veterans find jobs. The URL directs the victims to the fake site and prompts them to download an app, which was a malware downloader that deploys spying and other malicious tools.

70% of ICS Flaws Unveiled in First Half of 2020 Can be Exploited Remotely

CISA vulnerabilities, Microsoft Vulnerabilities, HP Device Manager Susceptible to Dictionary Attacks

A research from industrial cybersecurity firm Claroty revealed that around 70% of the industrial control system (ICS) vulnerabilities discovered in the first half of 2020 can be exploited remotely. In its report titled “Biannual ICS Risk & Vulnerability Report,” Claroty evaluated over 365 ICS flaws that were added to the National Vulnerability Database (NVD) and 139 ICS advisories issued by the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).

The number of flaws added to the NVD in the first half of 2020 is 10.3% higher compared to the vulnerabilities revealed in the same period in 2019, while ICS-CERT advisories increased by 32.4%. Around 75% of vulnerabilities were assigned high or critical Common Vulnerability Scoring System (CVSS) scores.

Nearly 50% of the detected security flaws can be used for remote code execution and 39% of them can be exploited for DoS attacks. While 41% of the flaws allowed a remote hacker to read application data, 37% of them allowed bypassing security procedures. The top three sectors affected by these vulnerabilities are energy (with 236 vulnerabilities), critical manufacturing (with 197 vulnerabilities), and water (with 171 vulnerabilities).

Amir Preminger, VP of Research at Claroty, said, “There is a heightened awareness of the risks posed by ICS vulnerabilities and a sharpened focus among researchers and vendors to identify and remediate these vulnerabilities as effectively and efficiently as possible. We recognized the critical need to understand, evaluate, and report on the comprehensive ICS risk and vulnerability landscape to benefit the entire OT security community. Our findings show how important it is for organizations to protect remote access connections and internet-facing ICS devices, and to protect against phishing, spam, and ransomware, in order to minimize and mitigate the potential impacts of these threats.”

5 Cybersecurity Trends to Watch for in H2 2020

Harness Your System, Free Decryptor, federal government, cybersecurity

The digital threat landscape is constantly changing. Such dynamism makes it impossible for security leaders to properly protect their organizations without formulating a carefully defined plan. They need a strategy through which they can adapt to new digital security threats and minimize risks confronting the business.

By Ali Golshan, Co-founder and CTO for StackRox

But how do they figure out where to direct their security efforts?

As a security platform for Kubernetes, StackRox has a duty to keep up with the latest cybersecurity threats and developments. Here are five trends in particular that we’ll be watching for the rest of the year. (Thanks to Built-In for providing an overview of these and other threats.)

Misconfigurations

Misconfigurations are not the products of software vulnerabilities or malicious hacking attacks. They are merely the result of human error. Indeed, misconfigurations emerge when security personnel and/or other employees fail to configure the settings on their software and hardware in a way that meets their organization’s digital security needs.

Misconfigurations take on various forms. For instance, misconfiguration events in cloud-based resources such as S3 buckets could enable anyone on the web to access and view an organization’s sensitive data. These types of incidents cost organizations approximately $5 trillion between 2018 and the end of 2019, as reported by TechRepublic.

Containers also suffer from misconfigurations. Indeed, a misapplied setting in a single container could enable a malicious actor to compromise an organization’s entire environment. Built-In notes this type of compromise is possible because containers share kernel space.

In response, organizations need to focus on baselining their assets and recording their security configurations. They should then monitor those assets over time for any deviances in behavior. Doing so could help defenders respond to a potential event more quickly.

Container and Kubernetes Vulnerabilities

Today’s containers are full of vulnerabilities. According to TechRepublic, a 2019 report found that the average container from the top 1,000 Docker Hub containers suffered from an average of 176 CVEs. The median CVE count for these containers was 37.

These security flaws pose a serious threat to organizations’ digital security. Attackers could abuse them to gain access to a container, for instance. Depending on the privileges involved with that container, they could potentially spread throughout the container environment and compromise an organization’s data.

Vulnerabilities aren’t just a concern when they affect organizations’ containers, either. Indeed, StackRox observed several vulnerabilities in 2019 that could bring down an organization’s entire Kubernetes infrastructure if they were successfully important. These security issues are especially concerning given the fact that Kubernetes generally releases vulnerability fixes for only the last three most versions of its platform. (That’s generally not the case with containers.)

As a result, security leaders need to make sure that they’re running a recently updated version if they hope to receive updates for vulnerabilities that could threaten the security of their organization’s Kubernetes environment. They should also regularly scan their containers for potential vulnerabilities. If they learn of any flaws that affect their Kubernetes or container environments, they should prioritize and schedule a patch as part of an ongoing vulnerability management program.

Microsegmentation

Trust is a crucial issue for organizations’ digital security. Too much trust means that there are few if any controls in place that limit which work resources are accessible to employees. That’s a problem, for if a malicious actor compromises an employee’s account, they could then abuse that trusting environment to move through the network and access sensitive data.

With increasingly complex IT infrastructure, organizations need to think about segmenting (and perhaps micro-segmenting) their networks. This isn’t always easy; microsegmenting a Kubernetes environment presents its challenges. For instance, with containers and microservices, organizations can’t use traditional firewalls or WAFs to enforce microsegmentation. That’s because containers and microservices are ephemeral and distributed in nature, while organizations need to account for North-South traffic along with traffic within pods (East-West).

Segmenting containers isn’t impossible, however. Organizations can use network policies to limit communication flows between pods and implement other means of segmentation. More guidelines on this topic are available here.

Greater Defender Accountability

The world is changing. With the introduction of new data protection standards and legislation such as the European Union’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), defenders’ employers are being held accountable for a digital security incident. This accountability isn’t just monetary in terms of paying legal fees and regulatory fines. It’s also reputational insofar as to whether consumers are willing to trust a victim of a particular security incident going forward. As more and more standards roll out, this monetary and reputational accountability for organizations will increase.

Fulfilling this accountability begins with defenders achieving complete visibility over their environments. Only by knowing what’s connected to the network can defenders figure out a way to protect them adequately. Through those measures, organizations can then develop a plan to respond to threats if and when they emerge.

Malware Abusing Containers

In the past few years, security researchers have detected several instances in which nefarious individuals abused Docker. Sometimes, they exploited open Docker API ports to mine for Monero cryptocurrency. Other times, they attempted to deploy botnet malware capable of conducting distributed denial-of-service (DDoS) attacks.

It’s reasonable to expect that incidents similar to those discussed above will continue to emerge over the next few years. Acknowledging that fact, organizations can’t ignore their container environments. They need to find a place for containers in their security strategies if they hope to protect themselves for the remainder of 2020. As part of this effort, they need to scan their containers for potential vulnerabilities and pull images down from trusted sources only.

About the Author

Ali GolshanWith a passion for building disruptive products, Ali Golshan is Co-founder and CTO for StackRox, where he oversees the company’s technology strategy and roadmap. Prior to StackRox, Golshan was the Founder & CTO of Cyphort (acquired by Juniper Networks) and led the company’s product strategy and research initiatives. Previously, he worked as a security researcher and engineer at Microsoft and PwC. Golshan started his career in Government conducting security and vulnerability research for the intelligence community.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article. The facts, opinions, and language in the article are entirely those expressed by the authors and do not reflect the views of CISO MAG. 

Singapore is Seeing Accelerated Digital Transformation, Yet Cybersecurity Remains a Concern

Singtel data breach

A recent survey from cloud-based communication platform Twilio found that COVID-19 had sped up digital transformation by an average of six years. This is because, for several organizations, business continuity now depends on their digital capabilities. But alarmingly enough, a report by Barracuda, a cloud-enabled security solutions provider, has found that even though the pandemic has accelerated remote working, digital transformation and cloud adoption, businesses are still a long way away from ensuring cybersecurity of its remote workforce.

 Key Findings 

  • In Singapore, COVID-19 has accelerated digital transformation by 83% and cloud adoption by 78%.
  • Companies in Singapore reported a 61% increase in business productivity since the shift towards remote working, with 81% planning to retain it even after the pandemic is over.
  • 51% of Singapore businesses report suffering at least one data breach or cybersecurity incident since moving to remote working.
  • 48% of businesses in Singapore do not have an updated cybersecurity strategy/solution in place to protect its remote workforce against potential threats.

COVID-19 is the Transformation Catalyst

According to the study, COVID-19 has been a prime catalyst for accelerated digital transformation and the key component of this transformation is cloud computing. On average, 78% of Singapore businesses have fast-tracked plans to move their data onto cloud. This specifically includes sectors like education (89%), IT and telecommunications (88%), manufacturing & utilities (86%), finance (75%), and healthcare (75%). Of the 204 Singapore-based respondents, 79% believed that embracing digital and the cloud will help reduce the overall IT costs and help support business growth in these testing times.

Barracuda report on remote workforce cybersecurity
Image Credit: Barracuda

The Other Side of the Coin

However, the flipside of this unprecedented transformation is the emergence of security challenges for businesses in the new normal. Already, more than half of Singapore’s organizations claim that they have suffered at least one data breach or cybersecurity incident since shifting to the remote working model, and nearly 48% said they expected an incident to occur in the coming month itself.

Barracuda report on remote workforce cybersecurity

Another alarming fact is that 53% of organizations allow employees to BYOD (Bring Your Own Device) for conducting office work. Personal devices are beyond traditional and advance security perimeters, and thus pose one of the greatest security threats to any business. Added to this, 48% of organizations in Singapore still do not have an updated cybersecurity strategy/solution. This further exposes the full-time remote workforce currently in place.

What Experts Say

James Forbes-May, Vice President, Barracuda, Asia-Pacific said, “Remote working is here to stay, but security must be addressed, and should not be an afterthought. Singapore businesses remain optimistic and resilient and as a hub of innovation and technology in the region; it’s encouraging to see businesses of all sizes here using this difficult time to accelerate exciting transformation plans. While many companies in Singapore are used to facilitating remote workers, the scale required due to the pandemic has left many companies CIOs and IT departments overstretched, as they jostle with business continuity planning as the key priority.”

“As a financial business center, companies in Singapore are particularly vulnerable to attack from fraudsters keen on exploiting any available weakness. Make sure to educate your employees around potential threats like phishing scams and ransomware. Additionally, have a cloud-enabled cybersecurity solution in place to monitor all traffic across the network. This could be the key to staying safe virtually in these unprecedented times”.

50% of U.K. Firms opt for Outsourced Cybersecurity Services: Report

Cybersecurity Skill Shortage Leads U.K. Firms to Outsourced Security Services

Shortage of skilled cybersecurity professionals continues to be a major concern for most businesses in the U.K., which made 50% of enterprises to opt for outsourced cybersecurity services to protect their digital ecosystems and customer information. According to a research from Skurio, a provider of Digital Risk Protection solutions, the lack of in-house expertise in handling cyberthreats or data leaks outside their perimeter is the key issue for most organizations, with 80% of respondents admitting that their security teams lack necessary skills in this area.

Around 52% of respondents said fulfilling the client’s data security requirements is the main reason for outsourcing cybersecurity services. The research also highlighted that IT and security pros differ in their views on this, with 50% of security experts prioritizing outsourcing services in reducing lost revenue due to business interruption, compared to 28% of IT staff. Also, 31% of security staff said security outsourcing is important to avoid fines, compared to just 17% of IT staff. While adopting new technologies, security leaders are twice as likely to choose a cybersecurity startup than their IT counterparts, with 31% and 16% respectively.

Jeremy Hendy, CEO of Skurio, said, “We’re facing exceptional circumstances in terms of working practices and how we need to manage cyberthreats, and this is placing significant pressures on businesses of all sizes. We know that the luxury of in-house security teams, on-call 24/7 to monitor for external threats, is simply out of reach for many organizations. The research highlights the importance of outsourcing to providers who make cybersecurity their business.”

Hendy added, “It’s encouraging that organizations not only recognize the importance of protecting their customer data but that there’s also an appetite for innovative and disruptive technologies to protect against new threats.  As organizations manage more digital channels and use more third-party suppliers, their threat vectors are rising exponentially. Understanding your digital risk – all those threats on the deep and dark parts of the web – is a great first step in protecting against them. Businesses are much better prepared to mitigate an attack if they see it coming.”

Cybersecurity Skills Shortage in U.K.

A similar research into the U.K. cybersecurity labor market by the Department for Digital, Culture, Media & Sport (DCMS) found an increase in the basic cybersecurity skill gap in most organizations in the country. The research  revealed that around 653,000 organizations (48%) in the U.K. are unable to carry out basic tasks defined in the government’s Cyber Essentials Scheme like setting up firewalls, storing data, and removing malware. It was found that 408,000 businesses (30%) lacked advanced cybersecurity skills in areas like pen testing, forensics, and security architecture.