How to Combat Common Information & Collaboration Security Threats

According to the World Economic Forum, cyber attacks are perceived as the number two global risk of concern to business leaders in advanced economies. This is second only to fiscal crises. Forbes reports that 17.2 billion records have been lost in the fifty largest data breaches between 2004 and 2021 - including a huge data breach for LinkedIn in 2021. 

The news is full of reports of these InfoSec attacks - whether phishing; stolen credentials; access because of unpatched or misconfigured software or social engineering attacks in which individuals are targeted within an organisation.

The British National Cyber Security Centre, however, singled out Ransomware as “the most significant cyber threat facing the UK” in 2021. CEO Lindy Cameron wrote: “...it was assessed as potentially harmful as state-sponsored espionage.” Indeed, ransomware was one of the topics tackled at the G7 Summit in 2021. 

This year, the annual review will no doubt add another few threats; and more countries and groups will appear on the list of prevalent threat actors, not least because the world continues to become more and more ideologically polarised.

State-level actors - from Russia, China, Iran and North Korea amongst other countries - have become stronger and are being protected

IBM’s Cost of a Data Breach report stated that the average cost of a data breach globally reached an all-time high of $4.35 million in 2022. While this figure is staggering by itself, what is also notable is that this is a 2.6 percent increase from 2021. Financial gain is definitely a motivation but there are also the hackers who cause disruption just for fun with no monetary motivation. 

Every single business is a target and InfoSec attacks are only going to become more subtle and more frequent. The very building blocks of encryption could be smashed down by quantum computing, warned The Economist and that was in 2018. 

This article reads like a declaration of doom, but it is actually a call to arms. Companies can protect themselves, but they need to invest heavily in talent, knowledge and expertise in cybersecurity. There is a scramble for cybersecurity experts as demand surges with students getting snapped up even before they have completed their degrees. In a climate in which businesses are terrified about the economic future, investing in cyber security is essential to protect themselves from losing vast amounts of money, if not everything, in just seconds. 

A clear place to start is to accept cybersecurity is not just as protection but as a business enabler.

A shift in mentality is required. A Cisco report stated that thirty-one percent of the survey’s 1014 respondents, who were senior finance and line-of-business executives, believed that the primary purpose of cybersecurity is growth enablement. However, sixty-nine percent still saw its main purpose as risk reduction. This view of cybersecurity - that and time-consuming and ineffectual tools - stymies creativity. In the same report, it states: “...A stunning 71 percent of executives said that concerns over cybersecurity are impeding innovation in their organisations. Thirty-nine percent stated that they had halted mission-critical initiatives due to cybersecurity issues.” 

On top of this, the time lost to rectifying the issues caused by an attack is also a business inhibitor. For some organisations providing critical and emergency responses, like the NHS, which was attacked in August, it can even be life-threatening. 

Then there is the impact of an attack on customer confidence. A major breach can damage brand reputation and customer retention as well as operations and finances. By deploying a steadfast cybersecurity plan and showing it is incorporated within your business’ governance, you are showing clients that you take cybersecurity seriously. Understanding this, and all of the other potential economic drivers and business impacts, will help you formulate a plan. This must include educating employees on cybersecurity to reduce human error and employing best practices instead of inventing your own methods and processes.

Ultimately though deploying simple, frictionless, and easy to use cybersecurity tools is going to be the quickest and most effective driver of change. This will motivate behavioural change, build confidence - both in your staff and clients - and boost instead of impede productivity. The InfoSec attacks may be becoming more targeted and frequent; but a simple, robust solution will prevail. 

Onur Özen is Chief Executive Officer of RealTyme

You Might Also Read: 

Building a Threat-Ready Ransomware Response Plan:

 

« Cyber Security Predictions For 2023
Simplicity In Complexity: The Key to Successful Threat Exposure Management »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Eden Legal

Eden Legal

Eden Legal provides legal services on commercial and regulatory issues affecting digital businesses.

I-Tracing

I-Tracing

I-TRACING are experts in IT security, specialized in legal compliance of information systems, security of information systems, and the collection of digital evidence and traces.

RiskIQ

RiskIQ

RiskIQ is the leader in digital threat management, providing the most comprehensive discovery, intelligence, and mitigation of threats associated with an organization’s digital presence.

Applied Risk

Applied Risk

Applied Risk is an established leader in Industrial Control Systems security, focused on critical infrastructure security and combating security breaches that pose a significant threat.

Shift Technology

Shift Technology

Shift Technology provides insurance companies with an innovative SaaS solution to improve and scale fraud detection.

Lirex

Lirex

Lirex offer consulting and outsourcing services, complete design, construction and maintenance of ICT solutions and systems including cybersecurity.

Maven Technologies

Maven Technologies

Maven Technologies specialize in secure data destruction, electronics recycling, asset management, and highly detailed reporting.

Allthenticate

Allthenticate

Allthenticate Single Device Authentication (SDA), enables seamless authentication in both the physical and digital words while unifying management in one easy-to-use interface.

Microchip Technology

Microchip Technology

Microchip Technology Inc. is a leading provider of smart, connected and secure embedded control solutions.

Guernsey

Guernsey

Guernsey provides a wide range of engineering, architecture and consulting services to multiple markets, including cybersecurity consulting and CMMC certification.

Peris.ai

Peris.ai

Peris.ai is a cybersecurity as a service startup that protects businesses and organizations from online threats.

Innov8tif

Innov8tif

Innov8tif is an AI company specialised in providing ID assurance solutions — helping digital businesses to prevent frauds by verifying and authenticating customers identity.

Praxis Security Labs

Praxis Security Labs

Praxis Security Labs is a research driven cybersecurity company that helps our customers to reduce risk and improve security.

Sensity

Sensity

Sensity is a company that offers an AI-driven solution to detect and verify deepfakes and other forms of identity fraud.

CIS Secure

CIS Secure

CIS Secure is an innovator, integrator and expert advisor supporting the broadest portfolio of powerful, mission-specific C5ISR communications and cybersecurity solutions.

Orchid Security

Orchid Security

Orchid Security provides unprecedented insight and action to your identity security with the help of advanced technologies like Large Language Models (LLM).