Addressing Cyber Threats With Positive Action

Hacking and other types of cyber attacks on business have increased considerably since 2018 and cybercrime in all its forms is hitting business with ever- increasing costs and so it is important to review your prospects and security against cyber-attacks in 2020/21.

The year 2018 was a watershed which saw a massive increase in global cyber-crime with Interpol reporting that it now runs in the billions of dollars. In the UK with 65% of large firms realised that they had been breached and attacked with ransomware  becoming one of the most lucrative sources of criminal profit.

Cyber criminals have learnt from their own successful experince and are now far more effective in their attack and theft processes. Many of cybercrime groups are now organising themselves along more traditional business processes which are are improving their effectiveness. Cyber crime is now the fastest growing areas of global crime and instead of a few small groups and some individuals committing the crimes. organiswed groups have grown and operate with a level of sophistication very similar  to large business models.

The crimes themselves have not changed dramatically as the criminals are still taking money from fraud, theft, gambling and illegal drug and fake medicine sales, but the expansion of the criminal activity to cyber-crime is far more effective and profitable for criminal business in general. 

  • The British Office for National Statistics (ONS) said in 2018 that computer misuse and malware against business was significantly increasing and was up 63% in a year.  
  • The Bristsish  National Cyber Security Centre (NCSC)  has said that cyber-crime has now reached its highest level to date and is asking all governments to advise all business to improve their cyber-security standards and actions.

The UK has made some progress but more police training is required as cyber-crime is now widkey considered to be equivalaent tpover 1% of UK GDP by the end of 2019. 

Other than a lack of real cyber training for all police officers, one of the current problems is that many businesses are still not reporting cyber-attacks and this reticence is usually connected with a fear of reputational dmage and related  public relations effects.

Cisco is now running a cyber security training programmed for 120,000 British police officers, although it is still the case that  reporting a cyber crime to the UK police in the UK is not easy. In the case of stolen personal banking data where victims have had their bank accounts robbed, the police often refer vistims back to their bank rather than dealing with the crime.  

The problem for the UK police is that they are overstretched with the numbers of police at its lowest level since 1981 and in many forces there is no capacity within the regional forces to spend the necessary time on cyber crime. Budgets for electronic systems has not for most governments, police services or commerce grown yet the potential for cyber-attacks has increased significantly and this reality will become more of a problem for many organisations over the coming months. 
There are no simple answers but staff training, understanding your security issues and more carefully managing your data has become crucial.  

There are a number of issues you should be monitoring including such areas as your use of cloud, training to reduce phishing attack effects and where a lot more different systems are connected. 

Often this is due to lack of training or when an employee leaves either through redundancy or because they have had an argument with their colleagues and or management or just because their access to the system has not been completely shut-down and so they still have access. 

The Costs Of Cyber Security
One of the issues that needs attention is to carefully budget for how much cyber security investment should be made and this should start with analysing how much an attack could cost and its effects. Getting an independent review of your systems and personnel cyber comprehension is very worthwhile and gives you a much better understanding of the risks and ways to improve the people and systems. 

Some of the broader issues that will affect organisations in 2019 will be due to AI and the ability to change and create fake news using video and audio spoofing.

One way this can affect you and your organisation is that these fake pieces can be used to get your staff to wrongly change something within the systems. Or it can create fake emails that con and mislead employees to pass over passwords or sensitive data and information. 

These effects can also be used to create fake news about a government or a company’s activities and it is very important that you tackle these issues by going through a thorough review and internal audit process will give business decion-makers a much better understanding of the potential issues and where positive action can take place 

You Might Also Read: 

Cyber Intelligence & Business Strategy:

Positive Cyber-Secure Training:

 

 

 

« Security Advice For Using Video Conference Tools
British Spies Looking For Private AI »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Assure Technical

Assure Technical

Assure Technical offers a holistic approach to Technical Security. Our expertise and services span across the Physical, Cyber and Counter Surveillance domains.

Virtustream

Virtustream

The Virtustream Enterprise Class Cloud provides a secure, highly available, Infrastructure as a Service (IaaS) to enterprises and government customers.

Simula Research Laboratory

Simula Research Laboratory

Simula Research Laboratory carries out research in the fields of communication systems, scientific computing and software engineering.

Subgraph

Subgraph

Subgraph is an open source security company, committed to making secure and usable open source computing available to everyone.

MASS

MASS

MASS provides world-class capabilities in electronic warfare operational support, cyber security, information management, support to military operations and law enforcement.

SecuLution

SecuLution

SecuLution is an Antivirus product using Application Whitelisting which offers much more protection than Virus Scanners ever can.

Aspen Insurance

Aspen Insurance

Aspen is a leading diversified specialty insurance and reinsurance company. Products offered include cyber insurance.

DQM GRC

DQM GRC

DQM GRC are one of the UK's leading providers of data governance, e-privacy and GDPR services, to commercial organisations across all industries in the UK.

Xilinx

Xilinx

Xilinx is the inventor of the FPGA, programmable SoCs, and now, the ACAP. We are building the Adaptable, Intelligent World.

DarkLight

DarkLight

DarkLight is a cybersecurity platform that mimics human thinking at scale to build resiliency to Advanced Persistent Threats.

Zacco

Zacco

Zacco offer a 360° perspective on intellectual property: From patent filing and trademark registration to software development, digital brand protection, cyber security and portfolio management.

DigiSec360

DigiSec360

DigiSec360 is a technology firm focused on the human element of cybersecurity.

SDG Corp

SDG Corp

SDG is a global cybersecurity, identity governance, risk consulting and advisory firm, addressing complex security, compliance and technology needs.

Ermes

Ermes

Ermes – Intelligent Web Protection provides companies with a solution that effectively secures them against web threats.

Lightpath

Lightpath

Lightpath is revolutionizing how organizations connect to their digital destinations by combining our next-generation network with our next-generation customer service.

Xantaro

Xantaro

Xantaro specializes in technologies, software and services for Carriers, ISPs, Hosting and Cloud Providers as well as for Operators of Data Centres and Campus Networks.