Home Blog Page 78

Do Digitally Connected Indians Feel Secure During the Pandemic?

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

The pandemic has changed our lifestyles in many ways, and the increase in digitalization is one of the major developments. People are digitally connected more than ever. Besides, the work from home culture and online learning certainly boosted the global digital connectivity amid the pandemic.

Looking at the spiking trend of online networking and accessibility, security solutions provider McAfee conducted the 2021 Consumer Security Mindset Survey,” which revealed that consumers in India are more cautious about the security of their connected devices. It also stated that 88% of Indian consumers feel they are more digitally connected and 86% have implemented more protection for their digital devices.

Key Findings

  • Nearly 57% of Indians agree that digital hygiene or the lack of it can put them and their families at risk.
  • 2 out of 3 Indians (68%) check if the network that they are joining is secure before connecting.
  • Increase in COVID-19-themed attacks targeting people working remotely.
  • 53% feel more vulnerable to risks when someone has visited their home and has connected to their internet.
  •  Perceived to be most vulnerable to cyberthreats are Wi-Fi networks (57%), someone’s home computer (46%), smart home assistants (26%), smart TV (28%), and gaming systems (29%).
  • 62% of the respondents believe that digital wellness and protection should have a separate curriculum and be taught throughout primary school. Online learners mostly concerned about exposure to scams (53%), sharing personal information (53%), illegal content (55%), cyber-bullying (52%), and misinformation (49%).

Increase in Cyber Hygiene

It was found that Indians are taking online security seriously — given the rise in COVID-19-themed attacks, which increased by 240% in Q3 and 114% in Q4 last year, with an average of 648 new threats per minute. Nearly 58% of Indians stated that they have a good understanding of the data they download/store on their mobile devices. Over 72% use a mobile security software solution to protect their mobile data, of which, 46% use preinstalled security software. And 58% of Indians believe that the information stored on their mobile phone is secure from cyber risks.

“Remote working, online learning, and a surge in the usage of connected devices due to more time being spent indoors have resulted in increased digital dependence among Indians. While our study indicates that more Indians are digitally connected owing to the pandemic, they are also now actively taking steps to keep themselves protected from online threats. The spike in our digital footprints during this time, makes it critical for everyone to understand the importance of online security and take measures towards protecting themselves,” said Venkat Krishnapur, Vice-President of Engineering and Managing Director, McAfee India.

How to Enhance Your Online Security? 

With rising attacks on connected devices, consumers must understand the seriousness of potential risks and must follow the required security measures to protect their personal information. Here are some security tips to enhance cyber hygiene:

  • Prioritize digital health by enhancing security standards across devices and home networks can also go a long way in maintaining digital wellness.
  • Use multi-factor authentication to double-check digital authenticity and add a layer of security to protect personal data and information.
  • Be cautious when connecting to any public Wi-Fi, or even your friend’s Wi-Fi connection, and make sure the network is secure and attached to a trusted source. Ensure that you don’t conduct any financial transactions or share any personal details while on an untrustworthy Wi-Fi network.
  • Separate your devices for business and personal use. We may have brought work home with us, but it’s important to set boundaries between personal and work life.
  • A comprehensive security software that can detect and block a variety of threats is always a good investment. Also, check if it includes a firewall, as this will ensure that all the computers and devices on your home network are well protected.

While we cannot expect 100% online data security, maintaining robust cyber hygiene will certainly help deter cyberthreats in the long run.

Don’t Get Doxed in a Doxing Attack

Doxing attacks

With digitalization at its peak, the internet is flooded with a copious amount of sensitive information. Besides following basic security measures, online users must adhere to additional precautions to secure their private information online. Cybercriminals have become more creative, leveraging different kinds of online attacks to pilfer sensitive data. One of the identity threats that users frequently encounter online is Doxing.

What is Doxing?

Doxing is an online attack used by identity stealers to harvest personally identifiable information (PII) and expose it online or use it for fraudulent activities. A doxer often tries to humiliate victims or threaten to leak their private data online. In doxing, information like name, contact details, social security number, home address, employer details, credit card numbers, bank account numbers, personal images, and social media profiles are often exposed or compromised.

How Doxers Harvest Users Data

It would be a surprise to many victims to know how hackers/doxers obtain their sensitive data without their consent. Most of the information could be harvested from your online platforms such as social media profiles or messaging forums, or through data breaches, stalking, phishing attacks. In addition, attackers approach third-party data brokers, who trade user data for monetary benefits.

Doxing Incidents

Threat actors and online abusers often dox celebrities and misuse their data to fulfill their malicious intent. For instance, Rap star Cardi B claimed that supporters of former president Donald Trump doxed her after she expressed her views online. The supporters reportedly posted Cardi B’s home address online and threatened to set her residence on fire.

Recently, Colorado State banned doxing of public health care workers due to the rise in online harassment.

Doxing Mitigation

Data privacy experts from Kaspersky have recommended certain online security practices that help prevent data privacy issues like doxing. These include:

  • Be conscious of which personal data you share and with whom, as well as how much you trust them.
  • Be mindful of who you share your data with and when.
  • Think before you post. Be accountable for what you share. Every time. Even if your account is closed.
  • Understand which messengers are safe and which ones have end-to-end encryption.
  • Make sure that you do not show your personal data on the photos you share.
  • Use abstract geotags if any at all. Do not tag photos with specific locations that you visit regularly.

Though the internet gives us space and freedom to publish our data, it is our responsibility to maintain robust online security practices to prevent various online threats like doxing.

South Korea’s PIPC Imposes Fines on Microsoft and Five Others Over Data Compliance Issues

South Korea's PIPC imposes fine

South Korea has been known for making huge strides in technological advancements. With companies like Hyundai, LG, and Samsung being the flag bearers, it has pioneered many tech and business solutions for the masses globally. However, one thing that not many people know about South Korea is that it takes its country’s data privacy and compliance seriously. A year ago, the South Korean telecommunication watchdog, Korea Communications Commission (KCC), found TikTok guilty of mishandling child data and thus had fined the company for 186 million won (approximately $155,000). Keeping a stern stance towards data compliance, South Korea’s Personal Information Protection Commission (PIPC) has now reportedly fined Microsoft and five other local companies on multiple counts of failing the country’s data protection laws.

The PIPC Imposes Fines

The fines imposed cumulatively total $75,000, of which Microsoft will pay 16.4 million won (approximately $14,700). Microsoft has been penalized on the pretext of failing to put in place appropriate protective measures on administrative accounts that eventually leaked over 119,000 email accounts, of which 144 belonged to South Korean citizens. This, however, was not the only count for the hefty penalty. Microsoft apparently announced the leaks within 24 hours of the incident as per the PIPC’s data laws – but in English. It took 11 more days to publish the data leak in the Korean language, which the PPIC said is mandatory for all Korean users.

The others in the list included a blockchain subsidiary Ground X and a known software company, Innovation Academy. Both companies were handed 25 million won ($22,400) each in fines for general privacy shortcomings. But, like Microsoft, both the companies were additionally charged on one count each. As per PIPC’s investigation, Ground X was found to have not protected their passwords efficiently and Innovation Academy was found guilty of a data leak that resulted in an extra six million won (approximately $5,400) and three million won ($2,700) fine respectively.

Besides, the World Math Fusion Olympiad Korea, the Korean Mountain Bike Federation, and the Korea Professional Football League were all slapped with a three million won ($2,700) fine for “data mismanagement.” In addition to the monetary fine, the football league was also asked to take corrective actions to fix the issues at the earliest.

Since the PIPC is an independent body established under the Personal Information Protection Act (PIPA), privacy rights and protection of personal data are a matter of utmost concern in the country. Hence, organizations in both the private and public sectors are required to comply with PIPA’s compliance and regulations.

Furthermore, South Korea’s Fait Trade Commission is also reportedly said to set up an investigation team to determine anti-competitive behavior and the amount of data collected by big tech.

Related News:

South Korea Penalizes TikTok for Mishandling Child Data

Lazarus Strikes Again, Attacks Supply Chain in South Korea

This is How Credential Phishing is Used to Compromise Email Accounts

Compromised Email Accounts

Despite stricter regulations over data protection globally, protecting user data has become increasingly essential. Ever wondered what happens to compromised accounts, how your leaked data is used by cybercriminals, or where it all goes? To answer these pertinent questions, email security solutions provider Agari conducted a survey to determine how attackers use credential phishing sites to pilfer passwords and how they exploit them post-compromise.

The survey “Anatomy of a Compromised Accountrevealed that 50% of compromised accounts in phishing attacks are accessed within 12 hours. It also found that cybercriminals try to exploit the stolen credentials as quickly as possible. In its six-month investigation, the Agari Cyber Intelligence Division (ACID) deployed more than 8,000 phishing sites mimicking popular brands such as Microsoft Account, Microsoft Office 365, and Adobe Document Cloud login screens. After submitting the login credentials, the research team linked individual phishing attacks to specific actors and their post-compromise actions to understand the lifecycle of the compromised account.

Key Findings

  • One in five accounts were accessed within the first-hour post-compromise.
  • Over 91% of all accounts were manually accessed by threat actors within the first week.
  • Scammers were located in 44 countries worldwide, with 47% in Nigeria.
  • Nearly a quarter of compromised accounts were automatically accessed at the time of compromise to validate the authenticity of the credentials.

How Attackers Exploit Compromised Accounts

Threat actors created fake applications including Microsoft OneDrive and Microsoft Teams to send phishing emails to targeted users and use the compromised accounts to set up additional Business Email Compromise (BEC) infrastructure. The research team claimed that scammers gained access to the compromised accounts to send vendor scam emails to high-profile employees who have access to the company’s financial information. The hacked accounts were also used for sending malicious emails and using the accounts to register for additional software to run their scams.

“Business email compromise or BEC remains the most prevalent threat in email security, and when cybercriminals gain access to legitimate email accounts, the problem is magnified. This research provides key insights into how cybercriminals use these accounts and underscores the importance of securing your email environment against credential phishing attacks from the beginning,” said Patrick Peterson, founder of Agari.

Scammers Found Using Compromised Credentials

The researchers stated that they have detected the actual location of cybercriminals associated with 41% of the compromised accounts. Most scammers are located in places like Eastern Europe, Russia, or North Africa. While Nigeria may be the primary location for users of compromised credentials, the second-most common location was the U.S., followed by South Africa, the UAE, the U.K., and Turkey.

BEC attacks are increasing exponentially. It is a severe security concern for organizations without proper security measures in place to protect against BEC and account takeover attacks.

How Communication Service Providers are Keeping the World Connected During COVID-19

Global Cybersecurity Outlook 2022,Cybersecurity, CEO, CISO

The extraordinary value of digital communications has never been more apparent than during the past year. As COVID-19 swept the planet, businesses and individuals switched almost overnight to remote working, relying more than ever before on digital channels to stay productive, informed, connected, and entertained. For communication service providers (CSPs), responding to the enormous and rapid change in usage patterns was an overriding priority. At the same time, the cyber threat landscape intensified, as malicious actors capitalized on disruption to launch attacks on distributed workplaces. This meant provisioning had to be balanced with maintaining security and resilience.

By Sanjai Gangadharan, Area Vice President, South ASEAN,  A10 Networks, and Adrian Taylor, Regional VP, A10 Networks

Now, more than a year since the onset of the pandemic, CSPs are analyzing the impact of the actions they took to meet surging demand and the broader range of locations they had to serve. They are adapting strategic investment plans to ongoing changes and identifying priorities for focus in the years ahead. At this critical point, A10 Networks surveyed more than 1,200 senior IT professionals, from a range of CSPs worldwide, to discover what lasting effects they are seeing on their subscribers and the enterprises they serve. The results reveal the extent to which “business-as-usual” is a thing of the past for global CSPs.

Changes in demand: immediate, universal, and here to stay

As billions turned to digital tools for news and to work productively, 99% of the service providers we surveyed saw a dramatic surge in demand, up by 55% on average. As a result, more than half of them scaled up infrastructure across their network, and 54% did so in specific high-demand locations. Faced with a much more distributed environment and a broader attack surface, 47% invested more heavily in security and 55% say this must be a priority for the future.

This is at least partly because the majority of service providers believe there has been a long-term change in how and where their customers expect employees to work. Two-thirds said that their customers will continue to operate with employees working from home post-pandemic. Consequently, relationships with customers have changed – 56% say customers are now demanding more self-serve options such as online portals, while just over half are seeing increasing customer concern about the resilience of their service provider and how it can underpin business continuity.

Certainly, awareness of the extent to which businesses and individuals rely on digital networks has grown exponentially in the past year, meaning service providers must focus on delivering highly reliable connectivity and minimizing any disruptive downtime. This was reflected in the investment priorities listed among the surveyed IT professionals: upgrading firewalls and security appliances, and adding DDoS protection and mitigation measures are all firmly in the roadmap for the coming year.

Overall, 52% of respondents plan to increase security investments over the next three years.

Enterprise customers face growing security challenges and are open to alternative providers as a result

CSPs are seeing customers striving to adapt to an escalating threat environment and a distributed network. Our survey respondents reported that many are pursuing better endpoint security, updating BYOD policies, and rolling out multi-factor authentication as they aim to mitigate growing cyberthreats.

Enterprise customers are also asking more rigorous questions of their service providers, requiring end-to-end security service level agreements in more than half of cases. Traditional CSPs must step up to this challenge and ensure that they can offer the protection and assurance customers need, because there is strong evidence that clients are prepared to look outside the conventional telco supplier list in a bid to enhance security. Three in five IT professionals surveyed said that enterprise customers are splitting workloads and traffic between traditional telcos and non-telco cloud platform suppliers to ensure resiliency. Correspondingly, half said that customers are now expanding their RFP list to include non-telco providers – a sign that this is a long-term strategy.

These changes to the customer purchasing strategy are significant and will see greater competition, with pressure on traditional telcos to offer more comprehensive services with uptime assurances that match rising customer demand.

5G and multi-cloud environments pose security concerns

The pandemic coincided with the rollout of 5G networks and precipitated a rapid shift to the cloud, giving service providers several fronts on which to manage major change. They anticipate a range of security challenges as the 5G shift progresses with the top concern being maintaining quality service and avoiding outages. One in five IT professionals said that unpredictable usage and changing traffic patterns were a top concern, while a similar number cited the growing threats of DDoS attacks on their now highly distributed network architecture.

Avoiding service outages was also a prime concern around managing subscribers across multi-cloud environments, together with compliance issues and ensuring a consistent subscriber experience.

It is evident from the concerns and priorities revealed by our research that service providers have customer experience and service resilience firmly at the top of their to-do lists as customer expectations, their purchasing strategies and the network environment undergo pandemic-accelerated change. A thread running through many responses was the threat posed by DDoS attacks, with almost half of service providers saying investment in DDoS mitigation across the network infrastructure was a priority, and the same number saying it is the top additional capability needed to protect against attacks that threaten network availability.

As service providers continue responding to the dramatic and widespread impacts of the pandemic, they will need to defend against non-telco competitors and deliver high availability and security assurance. Maximum uptime and data protection are paramount in the prevailing remote work environment, meaning investment in these areas will pay dividends. With a resurgence in DDoS attacks in the second half of 2020 – more than 12.5 million DDoS weapons were tracked by A10 researchers – this must be a critical area of focus.


About the Authors

Sanjai Gangadharan

Sanjai Gangadharan is the Area Vice President, South ASEAN,  A10 Networks. In his role, Gangadharan leads multiple teams of sales and sales consulting professionals that are focused on delivering A10 Networks’ next-gen security solutions to customers. Under his role, he continues to build and evolve A10 Networks to drive scale and revenue growth in the SAARC region, accelerate time to market, accelerate distribution, increase the company’s market share across all product lines and solutions and ensure customer satisfaction across SAARC regions. Leading the Indian business for over four years, Gangadharan has been empowering the Indian business to emphasize on innovation, develop business in emerging technology areas and manage strategic relationships with various stakeholders.

adrian-taylorAdrian Taylor, Regional VP, A10 Networks. Adrian is an established sales leader with over 25 years of experience in developing global and multinational accounts, across a wide range of emerging networking technologies. Joining A10 Networks in September 2018, Adrian is responsible for driving growth through direct customer engagements, as well as leveraging channel, service provider, and technology partnerships. Before moving into his new role, Adrian spent over three years leading software sales at Brocade, which was later acquired by Pulse Secure. Prior to this, he spent 13 years in senior positions at Cisco, where he first developed a strong understanding of cloud computing, while managing teams across EMEA and Russia, and driving a large proportion of channel and cloud sales for the business. Always one for a challenge, Adrian likes to push the limits within his role and explore new ways of driving A10 Networks’ product sales forward, while finding new and disruptive routes to market.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Focus on Cloud Data Protection Across Hong Kong Sees an Uptick: Study

Network Encryption, DSCI Whitepaper on Encryption

When it comes to technology adoption in the APAC region, Hong Kong has always been at the forefront. The same applies to their ardent attitude towards cybersecurity which was quite evident from their Cybersecurity Fortification Initiative 2.0 (CFI 2.0) that came into effect in January 2021. A new study by the Ponemon Institute highlighted that security and IT professionals in Hong Kong continue to outpace the global average when it comes to the adoption of enterprise-wide encryption, with a particular focus on cloud services, applications, and containers. The study additionally reports the cybersecurity challenges that organizations face today and the subsequent contributing factors of how and why organizations deploy encryption.

The Threats and Priorities

For the second consecutive year, 54% of respondents in Hong Kong said that they have adopted a consistently applied encryption plan/strategy. These numbers are well ahead of the global average, which stands at 50%. Also, for the second straight year, the people of Hong Kong believe that the biggest threat to the exposure of sensitive data was employee mistakes (47% vs. 53% globally) and system or process malfunction (36% vs. 31% globally), followed by hackers (33%).

The survey also revealed Hong Kong’s dependence on cloud technology as around 6 in 10 (59%) organizations reported transferring data to the cloud. This is up from 55% last year and is expected to surge an additional 24% in the next 12-24 months. Similarly, just over half of organizations said that they deploy encryption for the public cloud services (51% vs. 46% globally) which they use extensively. In doing so, the Bring Your Own Key (BYOK) management support has been cited as the fastest-growing feature of cloud encryption solutions (53%). Furthermore, nearly half (47%) of IT professionals in Hong Kong deploy encryption for containers, the highest rate worldwide, up from 40% last year and far above the global average of 32%.

Greater Adoption of Hardware Security Modules (HSMs)

The issues associated with key management are increasingly seen in the organizations in Hong Kong as two-thirds reported a high rate of overall pain associated with managing keys or certificates. This is up from 61% last year and higher than this year’s global average of 56%. Talking about the factors for driving it, the majority of the respondents suggested that there is “no clear ownership” (74% vs. 64% globally), with inadequate key management tools in second place (58% vs. 46% globally).

These results indicate the importance of HSMs to encryption or key management strategy. It is expected to increase from 63% to 79% over the next 12 months. Similarly, with the increased focus on cloud migration, organizations in Hong Kong prefer using HSMs that they own and operate (54% vs. 41% globally).

Michael Tai, Area Vice President of Greater China at Entrust, said, “Organizations in Hong Kong are increasing their use of the cloud and containers as IT and security professionals focus on the risks associated with employee mistakes and system or process malfunctions. As they strive to protect customer information and intellectual property and to comply with data privacy mandates, organizations on average now use more than eight different products that perform encryption. This brings new challenges associated with discovering where sensitive data resides, deploying encryption technology, and training users to use encryption appropriately.

Key management still causes a high level of pain, due to concerns about key ownership and inadequate key management tools. As they deploy encryption for databases, containers, and cloud applications, organizations in the region seek encryption solutions that offer scalability, tamper resistance with an HSM, but as cloud use increases, organizations prefer to own and manage the HSMs used to protect cloud applications.”

Related News:

Hong Kong Set to Embrace Cybersecurity Fortification Initiative 2.0

New York City Law Department Hit by a Cyberattack

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

The year 2021 is probably going to witness a series of high-profile attacks on almost all sectors. From the fuel supplier Colonial Pipeline, laptop maker Acer, to meat processor JBS, cybercriminals are targeting all kinds of industries. The latest sector to suffer a cyberattack is the New York City Law Department.

According to a report, a sophisticated attack forced the law agency to go offline. The city’s Cyber Command detected unusual activity on the Law Department’s computer network. Upon discovering the attack, the officials immediately disconnected the department’s computers and network systems from the city’s network. While it is unclear who is behind this cyberattack, the mayor of New York City, Bill de Blasio, said there is no sign of misuse of data, however added that the situation was “emerging.”

The New York City Law Department has over 1,000 lawyers and 890 support professionals. A data breach could affect sensitive information belonging to thousands of employees in the department.

“To this hour we have not seen information compromised or a ransom demand. As the investigation remains ongoing, the City has taken additional steps to maintain security, including limiting access to the Law Department’s network at this time. We do fully expect the law department IT environment will be securely reestablished promptly so the law department can get back to the business of serving New Yorkers.

I think people should realize this is something that’s going to be with us for quite a while. And we’re going to have to do a lot to focus on it and constantly protect ourselves,” de Blasio said.

What Experts Say…

Talking to CISO MAG, Shana Simmons, General Counsel at Everlaw, said, “From SolarWinds to Colonial Pipeline to JBS, bad actors are making their way through the most lucrative and impactful businesses and infrastructure – law was inevitably next. While we’re still learning whether any data was stolen from the NYC Law Department in the latest cyberattack, law firms and departments are increasingly an attractive target because of the sensitive nature of their business. From corporate legal and M&A work to litigation and other legal services, they handle large volumes of confidential and personally identifiable information.”

“Yet security loopholes remain: A report from the American Bar Association last year found that only 43% of attorneys use file encryption and less than 40% use email encryption, two-factor authentication, and intrusion prevention. This is concerning, especially for departments that hold the keys to some of the most sensitive data.
Bad actors are on a tear this year, and they’re showing no signs of slowing down. As a result, law firms and departments need to practice safe cybersecurity measures such as: enabling two-factor authentication, backing up data, keeping software patched, and training employees on best security practices,” Simmons added.

This is not the first time that attackers have targeted a government agency to steal data. The intelligence bureau of the New York Police Department (NYPD) and the FBI’s cyber task force are investigating the cyberattack. Although no ransom has been demanded yet, the NYPD hasn’t ruled out the possibility of a ransomware attack.

DNS Attacks Surge by 15% in APAC; India Among Worst Hit Nations

DNS attacks

Ever since the pandemic hit, the global threat landscape grew more vulnerable, with a wider impact on the cybersecurity community. And this is just the beginning. According to the 2021 Global DNS Threat Report from network security automation solutions provider EfficientIF, nearly 90% of organizations have suffered a Domain Name System (DNS) attack last year. Cybercriminals are leveraging multiple hacking techniques to pilfer sensitive digital assets, and one of them is DNS attacks.

What is a DNS Attack?

DNS is a protocol that translates a domain name into an IP address. In a DNS attack, adversaries exploit vulnerabilities in the domain name system to obtain access to targeted devices. They also pharm and phish users to generate revenue and steal critical data. DNS is leveraged to launch attacks in multiple ways, including DNS reflection attacks, DoS, DDoS, and DNS poisoning.

“This past year of the pandemic has shown us that DNS must play a role in an effective security system. As workers look to more permanently transition to off-premises sites, making use of cloud, IoT, edge, and 5G, companies and telecom providers should look to DNS for a proactive security strategy. This will ensure the prevention of network or application downtime as well as protecting organizations from confidential data theft and financial losses,” said Ronan David, VP of Strategy for EfficientIP.

Key Findings

  • Malaysia experienced the highest increase of 78% in the cost per attack, with an average cost per attack of $787, 200. The two countries among the top three are India and Spain.
  • In Asia, while India experienced an increase of 32%, Singapore’s damages declined by 12%, against the regional average increase of 15%.
  • Asia experienced a sharp rise in damages of $908,140, compared to last year’s $792,840. The countries that saw average damages above $1,000, 000 were India, France, and Germany.
  • 26% of organizations reported sensitive customer information being stolen, compared to 16% in 2020.
  • Phishing also continued to grow, with 49% of companies experiencing phishing attempts. In the Asia Pacific, the phishing rate was as high as 46%, with nearly half experiencing a phishing attack included India, Singapore, and Malaysia the most-experienced type of attack including malware-based attack, domain hijacking, cloud misconfiguration abuse, tunneling, and zero-day vulnerability.

The Impact of DNS Attacks

The report revealed that downtime of in-house and cloud applications remains the major impact of DNS attacks, indicating how critical DNS is to ensure resilience and to secure access between users and applications.

“The impact and cost of attacks remain extremely high and continue to increase year over year. This not only affects company finances but also brand image and data confidentiality. With the pandemic, ransomware has increased to become an industry in its own right and a major concern for most organizations. Using DNS filtering and blocking is critical as it can help to stop ransomware attacks right after the infection when the malware tries to contact command and control,” the report stated.

Top 5 Cybersecurity Trends Businesses Should be Aware of in 2021

return to office, business, hybrid work

2020 will go down in the annals of corporate history as a game-changing year. Even now, as we slowly begin to emerge from a pandemic that forced entire countries into lockdown, our collective economic futures are still shrouded in uncertainty. Those businesses that have managed to weather the turbulence have had to undergo significant change, with some industries reportedly cramming a decade’s worth of digital development into the space of 90 days in something McKinsey calls The Quickening. 

By Jon Lucas, Co-director of Hyve Managed Hosting

However, with rapid change comes vulnerability, and where there is security there is often complacency. Whenever the status quo is threatened, those that have found relative stability are often the first to fall as bad actors seek to take advantage of the turmoil. The past year’s global migration to the cloud due to the pandemic is just the latest in a series of black swan events that cybercriminals will be seeking to capitalize on, but this time many businesses have been caught well and truly on the back foot. In this article, we’ll take a look at the top five cybersecurity risks and trends to look out for as we navigate the choppy waters of 2021.

State of play

Since the pandemic and the virtual wholesale migration to remote working, nearly 70% of business leaders became acutely aware of their cyber vulnerability increasing. In the U.S., the FBI has reported a 300% increase in the number of cyberattacks since early 2020, and recent data published by Google showed a staggering 18 million daily phishing attempts at the start of the pandemic. A report by Verizon reveals that the number one motivation for cybercrime in 2021 is financial gain and exploitation, which effectively puts any business at risk regardless of sector or industry.

These figures are alarming, but they’re not necessarily news. Cybercrime has been steadily rising for years, both in frequency and sophistication. But there’s something about 2020/21 that should make us sit up and pay attention. The landscape has changed. Businesses are now at more of a disadvantage than they were prior to the pandemic, with many having completely changed their working culture and technology architectures. So what has changed? And what should businesses be especially mindful of?

1. The target on the backs of businesses is now much bigger 

One of the biggest dividing lines between pre-pandemic and post-pandemic is the ‘surface area’ cyberattackers now have to work with. Many businesses that were previously based on-premise in an office, working on a private network, are now suddenly adapting to a hybrid environment where half their workforce might be working at home at any given time. While VPNs and virtual desktops will prove invaluable, there’s no doubt that a distributed workforce hopping from device to device – and often throwing their own personal devices into the mix – will be a huge security headache in 2021.

2. Our digital footprint is about to explode 

By 2025, more than 200 zettabytes of data will be stored on the cloud. Digitalization has always been on the cards, but the pandemic has accelerated this process at an unnatural rate. Businesses that worked hard to adapt quickly following the pandemic will have been tempted to cut corners and perhaps leave themselves more vulnerable than if they had taken a gradual, phased approach. With so much data moving online so suddenly, and security infrastructure playing catch-up, we’re likely to see cybercrime increase in volume in the years following the pandemic.

3. Expect to see a lot of ransomware headlines

Ransomware might be more than two decades old, but it’s now the weapon of choice for attackers that want to exploit business for financial gain. Some estimate that there are now more than 120 ‘families’ of ransomware, and hackers are employing increasingly more sophisticated methods when it comes to hiding malicious code. So-called ‘double extortion’ ransomware cost businesses $8 billion in 2019, $20 billion in 2020, and we’re likely to see that trend continue throughout 2021 and beyond.

4. Critical Infrastructure (CI) will be highly targeted

The World Economic Forum published a paper that revealed attacks on critical infrastructure (CI) have become the “new normal” across the energy, health care, and transportation sectors. Most CI infrastructure is particularly vulnerable because of the sheer surface area attackers have to work with, with no shortage of network endpoints to exploit. The now infamous SolarWinds breach in 2020 is the biggest warning sign yet of CI becoming a new target for cybercriminals.

5. Old fashioned brute force attacks are back with a vengeance

The latter half of 2020 saw a 12% uptick in the number of DDoS (distributed denial of service) attacks against corporations. Using botnet swarms, attackers aim to overwhelm networks with IP requests and slow response times – in some cases completely sidelining entire services. Expect to see DDoS attacks brute force their way back into the conversation in 2021 and beyond.

The much anticipated “new normal” might still be a way off, but one thing is for certain – cybersecurity is going to be a huge part of the conversation moving forward.


About the Author

Jon LucasJon Lucas, along with his business partner Jake Madders, founded Hyve Managed Hosting, in 2001. Since then, in his role as Director, Jon has facilitated the growth of Hyve from a small start-up to a hugely successful managed cloud hosting company with a global customer base. With a background in software development, Jon has spent time at Crédit Agricole, Goldman Sachs, JPMorgan Chase, and M&C Saatchi throughout his career.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

How to Become a Digital/Computer Forensic Analyst in 2021

Digital Forensics

Handling a cybersecurity incident is not an easy task. Cybercriminals often leverage advanced hacking techniques to evade detections and leave no clues about their malicious activities. This is where a computer or digital forensic analyst comes into play. In addition to cybersecurity readiness, organizations must employ a cyber forensic team to analyze a cyberattack and trace the actor behind it.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is Digital Forensics?

Digital forensics or computer forensics is a field of uncovering, identifying, extracting, and documenting evidence after a cybersecurity or data breach incident. The digital artifacts found by the forensics team can be used to determine the culprits and help in law enforcement proceedings. Digital forensics is a critical category in cybersecurity with several branches including, firewall forensics,  network forensics, computer forensics, database forensic, and mobile device forensics.

A forensic team is responsible for retrieving deleted, lost, manipulated, or stolen data. They are required to work closely with the law enforcement authorities to investigate cybercriminal activities.

Digital Forensics vs Computer Forensics

Though the two approaches have the same purpose, digital and computer forensics differ in their investigation processes. Digital forensic investigation includes gathering digital artifacts such as mobile phones, networks, USB drives, hard disks, CDs, digital cameras, and electronic files like JPEGs, and emails. Computer forensics is mostly limited to computer analysis to find the evidence.

What Skills are Required?

For one, you need to have an investigative mindset and good problem-solving skills. Most organizations are deploying a digital/computer forensic analyst in their security team to boost their incidence response plan.

Requirements

  • Bachelor’s degree in computer science or cybersecurity
  • Work experience in a related field would be an added advantage
  • Good investigation and presentation skills
  • Knowledge in cyber law and criminal investigation
  • A sound analytical mind with attention to detail

Certifications

In addition to academics, relevant certifications will help individuals excel in the digital forensic field. Get started with EC-Council’s certifications like:

The eligibility criteria for forensic analyst varies from one company to another. But most organizations are willing to employ one due to rising cyberattacks and to meet audit and compliance requirements.

Cybersecurity is an ocean of exciting opportunities, there are multiple reasons to pursue one.

About the Author:

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.