Is Your Anti-Virus Doing Its Job?

Every day, new malware and other online threats emerge. In fact, the AV-Test Institute registers over 380,000 new pieces of malware and potentially unwanted applications (PUA) every day.

The 2022 report from the Department for Digital, Culture, Media & Sport ‘Cyber Security Breaches Survey’ reveals that bad actors are still largely targeting people, instead of infrastructure. For those medium and large businesses that identified an attack, the most common threat vectors were phishing attempts (94%) and impersonation campaigns (63%).

However, Digital Pathways research shows that many mid-market businesses do not believe their current cybersecurity strategy is future ready.

Phishing campaigns are evolving, and cyber criminals are getting increasingly sophisticated, often using relevant news and trends as click bait. COVID-19, humanitarian efforts in Ukraine and even popular, sporting events, have all been used to lure victims into clicking a malicious link or opening a corrupted attachment on email.
Some operating systems are much more susceptible to viruses than others, with Windows coming in first, with 87% of ransomware targeted at Windows computers.

In a world where cyber attacks are growing, traditional anti-virus solutions are simply not enough. As confidence in detection-based protection is declining and given remediation even for a single threat is increasingly costly, now is the time to introduce more preventive anti-malware solutions.

This is supported by a recent study by the Ponemon Institute on the state of endpoint security risk, where they found that only 27% of respondents thought that traditional anti-virus solutions were sufficient for new and unknown threats.

The reality is, with our increased reliance on being connected to the web, combined with the rapid expansion of malware, it is becoming harder to prevent devices from getting infected. That means, if you are relying on anti-virus software alone to secure your PC, you do not have enough protection against the growing number of threats. There are too many threats to defend against!

Standard anti-virus software is effective against most known threats. But there are also unknown risks to add into the equation, and this is where they fail. AV engineers need time to understand a new virus and then add the fix to their software which can take days to do. Then a further delay happens as IT teams often do not update immediately. Thus, an update could take a week to be implemented which, in virus terms, is ample time to spread.

Something as seemingly harmless as a web page can be a way for malware to get into your system, simply by visiting them. These typically come from clicking malicious ads, known as malvertising attacks, they land on a page that could download a file or execute a web script that compromises your system.

Given the findings that many companies do not have a clear strategy for tackling these attacks, and where they do, the process is disjointed or out of date, what can an organisation do?

  • Start by taking back control and protecting users from traditional email threats including spam, viruses, large-scale phishing attacks and malicious URLs.

To do this, ensure your solution can address both known viruses, and fileless attacks, such as those coming from websites or, brand-new viruses which have yet to be diagnosed by the AV vendors.

  • Secondly, close any gaps in existing security postures by integrating attack intelligence across email, web, and cloud, using identity and context.

This is about looking at the bigger picture and ensuring bad code is not already in the network, waiting for the trigger to be pulled. Use behavioural analytics, the more granular your data, the better the understanding of what constitutes normal activity, enabling anything unusual to be flagged for review.

  • Thirdly, prevent cross-channel attacks with an autonomous security engine that can respond to any threats at machine-speed.

This helps ensure that when an attack is seen in one location, for example a device within the network or a rogue weblink, all connected devices and services within the organisation are protected by machine level alerts, which contain the outbreak or remove the weblink by filtering from any other user. Remember ransomware tactics are diversifying and can strike at weekends or holidays when fewer IT security staff will be on duty.  This calls for an AI level of monitoring and response.

  • Finally, run regular phishing simulations which are a good way to keep employees sharp, particularly live tests and never underestimate the insider threat.

It is a fact that AV alone is not good enough, and an organisation needs to take a broad approach to stopping bad code entering the network.

Clearly user education is a good starting point, but on its own the company will still suffer a breach, no matter how diligent users are.

Today, the attack surface is so wide that what is needed, is a consolidated solution that covers email, websites, and active content scanning, built around an AI driven intelligent process of detection, containment and remediation, as we are now beyond the ability of most IT teams to fully understand what the attack vector is.

Colin Tankard is Managing Director of Digital Pathways

You Might Also Read:

Never Trust Anything Again - The Zero Trust World:

 

« A Major Skills Training Initiative From (ISC)2
How IAST Improves Application Security & Six Steps to Effective Deployment »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Sophos

Sophos

Sophos is a worldwide leader in next-generation cybersecurity, protecting more than 400,000 organizations of all sizes in more than 150 countries from today’s most advanced cyberthreats.

GovCERT.CZ

GovCERT.CZ

GovCERT.CZ is the Government Computer Emergency Response Team of the Czech Republic.

Visa

Visa

Visa is a global payments technology company that connects consumers, businesses and banks in more than 200 countries and territories worldwide.

Nohau

Nohau

Nohau provide services for safe and secure embedded software development.

CyberPoint

CyberPoint

CyberPoint delivers innovative, leading-edge cyber security products, solutions, and services to customers worldwide.

Galvanize

Galvanize

Galvanize is a leading provider of award-winning, cloud-based security, risk management, compliance, and audit software for some of the world’s largest organizations.

CyberForce Program - US Department of Energy

CyberForce Program - US Department of Energy

The Department of Energy’s (DOE) CyberForce Program is a workforce development program that seeks to inspire and develop the next generation of cyber defenders for the energy sector.

Netmarks Indonesia (NMID)

Netmarks Indonesia (NMID)

Netmarks Indonesia is an IT solutions provider offering services related to ICT infrastructure, digital transformation and cyber security.

GOVCERT.lu

GOVCERT.lu

GOVCERT.lu is responsible for the treatment of all computer related incidents jeopardising the information systems of the government and defined critical infrastructure operators in Luxembourg.

Hexnode MDM

Hexnode MDM

Hexnode MDM is an award winning Enterprise Mobility Management vendor which helps businesses to secure and manage BYOD, COPE, apps and content.

Q6 Cyber

Q6 Cyber

Q6 Cyber is an innovative threat intelligence company collecting targeted and actionable threat intelligence related to cyber attacks, fraud activity, and existing data breaches.

Secure Digital Solutions (SDS)

Secure Digital Solutions (SDS)

Secure Digital Solutions is a leading consulting firm in the business of information security providing cyber security program strategy, enterprise risk and compliance, and data privacy.

SpecterOps

SpecterOps

SpecterOps has unique insight into the cyber adversary mindset and brings the highest caliber, most experienced resources to assess your organizations defenses.

Nineteen Group

Nineteen Group

Nineteen Group delivers major-scale exhibitions within the security, fire, emergency services, health and safety, facilities management and maintenance engineering sectors.

SpeQtral

SpeQtral

SpeQtral offers commercial space-based Quantum Key Distribution (QKD) founded on technology developed at the National University of Singapore.

Acora

Acora

Acora provide a range of best-in-class managed services, Microsoft-centric business software, and cloud solutions designed to help mid-market organisations succeed in the digital economy.