A Perfect Storm For Cybercrime

Calling the past few years uncertain is a slight understatement. From the COVID-19 pandemic, through to record inflation, the exhaustive energy crisis, and the devastating war in Ukraine - so many drastic events have had a significant impact on global behaviour and livelihood.

Every time the world stops to give people a moment to catch their breath, it seems another crisis comes along to disrupt things even further. This has led some global experts to even go as far to describe the world as in a state of “permacrisis”.

The effect these events have bleed through into all facets of life, but from a cybersecurity aspect, the fallout can be even more significant. The ambient uncertainty arising from the unknown plays a huge part in the funding and resourcing behind security operations (SecOps) teams – especially when board members don’t fully understand why having robust cybersecurity tools is so important to protecting business interests.

Furthermore, we’ve also seen threat actors play into the geopolitical instability, utilising sophisticated spear-phishing techniques to target individuals in critical sectors. In some cases, these have been backed by foreign governments in an effort to further destabilise regional economies – we’ve seen this recently with China’s activity in Taiwan. The question arises as to how businesses can better protect themselves from this malicious activity.

New Threats Rising To The Surface

As the tools supporting cybersecurity teams grow more sophisticated, so do the tools utilised by threat actors in their initiatives. Recent research from Trellix found that growing attack surfaces comprise 34% of the challenges faced by CISOs in protecting their organisations. But how does the threat landscape take shape – from ransomware to email, network, and endpoint vulnerabilities?

It’s difficult to pinpoint the exact vectors that threat actors utilise in compromising victim systems. Over the past year, we’ve seen a significant increase in the exploitation of Living off the Land Binaries (LotLBins), with threat actors gaining access to IT infrastructure through existing, benign system tools.

With this, we’ve also seen a proliferation in the use of first and third party bespoke and open-source tools such as Ghidra. Unpredictability on the part of malicious groups is an increasingly leaned on tactic, but it reinforces the importance of security being at the forefront of business decisions. 

According to CISOs across the globe, employee error, such as accidently downloading compromised files or clicking malicious URLs, directly led to 45% of breaches in 2022. Having a top-down, security minded culture is essential to ensuring all business units are informed about security procedure.

Since the start of the conflict between Ukraine and Russia, we’ve also seen increase in niche strategies employed by groups, such as hacktivism – the use of hacking skills to promote political or societal change. Whilst hacktivism isn’t a new trend, groups like Anonymous have existed for some time now, these world events have initiated a “call-to-action” so to speak, against perceived societal injustices.

Collaboration Is The Key Ingredient To Protection

The uncertain political and economic environment has triggered a paradigm shift in attitudes between nations and organisations. The state of permacrisis has been a catalyst for important partnerships between the public and private sectors. We’ve seen an increased coalition of data between large cybersecurity industry players like Microsoft, Cisco, Google and Trellix, leveraging intelligence with the Ukrainian government and NATO throughout 2022.

Increased activity between the Five Eyes alliance (Australia, Canada, New Zealand, the United Kingdom, and the United States), as well as the EU has helped in limiting the scale of state-backed cyberattacks.

The UK government has also recently announced it is strengthening its ties with Japan and Israel to enhance tech and security collaboration between the countries and reduce cyber risk. Whilst advanced persistent threat (APT) groups still remain active, partnerships like these have enabled companies and governments to be better prepared in the face of emerging threats.

Tracking major APT groups is an ongoing process. It requires the participation of government bodies and businesses to keep atop of the evolving threat landscape and minimise threats. Sharing intelligence with the NCSC and CISA, for instance, is an essential step in mitigating the impact of security breaches. To this end, the formation of groups like the NCSC’s Industry 100 scheme and the CISA’s Joint Cyber Defence Collaborative (JCDC) are facilitating a collaborative and fluid intelligence highway across public and private sectors.

Ever Looming State-backed Threats

In May, the APT Group known as Volt Typhoon mounted a massive cyberattack aimed at crippling US critical infrastructure. Whilst they deny involvement, evidence that China was involved in backing the group in their activities demonstrates the building tensions between the East and West. This coincides with our own findings within the recent Trellix CyberThreat Report, with China being the most prevalent threat actor country, contributing to 79% of state backed activity worldwide in Q1 2023.

The exploitation of LotLBins allowed Volt Typhoon to remain hidden amongst in-built systems on compromised computers. This enabled them to remain undetected whilst moving laterally through systems, expanding their threat surface. Often organisations will not even know there is a breach until it is far too late - investing in resources that enhance existing incident detection and response capabilities is crucial.

Cybersecurity is a shared problem. Robust, real-time sharing of threat data is key to protecting citizens and organisations from attack.

The mentality needs to be that “the enemy of my enemy is my friend” when it comes to true security collaboration to keep cybercriminals at bay.

Centralising Security Operations

There is pressure on SecOps in making do with the tools that are already in place. Much like spinning plates, too many siloed solutions can inadvertently take control away from security professionals and reduce overall security visibility.

Having a centralised system that covers email detections, endpoint, network protection and control over data migration offers greater protection.

This allows core vulnerabilities to be prioritised, whilst additional tools like AI and machine learning can be introduced for more automated detection and response. Agility and flexibility are key, as threat actors are always learning, adapting, and evolving their attack techniques. When faced with this challenge, agile cybersecurity defence based on frontline intelligence becomes crucial when defending against attacks across both public and private sectors.

Fabien Rech is Senior VP & GM EMEA of Trellix

You Might Also Read: 

Overcoming The Obstacles Caused By The Great Resignation:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

 


Cyber Security Intelligence: Captured Organised & Accessible


 

« A Million British Medical Patient Records Hacked
Sweden Issues An Order 'Stop Using Google Analytics' »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Pluralsight

Pluralsight

Pluralsight helps enterprises build technology skills at scale with expert-authored courses on today’s most important technologies including information and cyber security.

Kaseya

Kaseya

Kaseya is a premier provider of unified IT management and security software for managed service providers (MSPs) and small to medium-sized businesses (SMBS).

Asigra

Asigra

Asigra provides an industry leading cloud backup and recovery software platform called Asigra Cloud Backup.

Feedzai

Feedzai

Feedzai provide software that uses big data analysis and machine-based learning to prevent fraud in ecommerce.

Onapsis

Onapsis

Onapsis is a pioneer in cybersecurity and compliance solutions for cloud and on-premise ERP and business-critical applications.

ICS2

ICS2

ICS² is the first cyber security company focusing on protecting the control system of power, oil, gas, and petrochemicals plants.

Checksum Consultancy

Checksum Consultancy

Checksum Consultancy specializes in Information security, Risk management, and IT governance.

EUROCONTROL

EUROCONTROL

EUROCONTROL is a pan-European, civil-military organisation dedicated to supporting European aviation. We help our stakeholders protect themselves against cyber threats.

Cybersecurity Innovation Hub

Cybersecurity Innovation Hub

Cybersecurity Innovation Hub is a non-profit network organization focused on cooperation, information sharing, research and implementation of cutting-edge technologies in cybersecurity.

Axis Security

Axis Security

Axis Security technologies transform open networks and vulnerable applications into fully protected resources that the business can trust.

Canopius Group

Canopius Group

Canopius is a global specialty lines insurance and reinsurance company and one of the top 10 insurers in the Lloyd’s insurance market.

Cyber Griffin

Cyber Griffin

Founded by the City of London Police in 2017, Cyber Griffin is an initiative that supports businesses and individuals in the Square Mile to protect themselves from cyber crime.

Open Quantum Safe (OQS)

Open Quantum Safe (OQS)

The Open Quantum Safe (OQS) project is an open-source project that aims to support the development and prototyping of quantum-resistant cryptography.

Ventum Consulting

Ventum Consulting

Ventum Consulting stands for digitalization, networking and agilization. We take this up on the strategic, professional and technical side and support our customers in the digital transformation.

CyberForce Global

CyberForce Global

CyberForce Global are at the forefront of start-up technology recruitment in areas including cybersecurity, IT infrastructure, software, fintech, blockchain and more.

Accompio

Accompio

Accompio offer comprehensive support in the digitalisation of your business processes.