New studies highlight growing cyber threats and associated resource concerns
- Date: 25 June, 2021
A raft of new studies have highlighted the ever-increasing range of cybersecurity threats that organisations of all sizes are facing and how these are being compounded by inadequate user awareness and a lack of security professionals with the requisite skills.
It’s certainly been a busy time for research activities within the cybersecurity space, with a number of new studies providing insights into the challenges that security teams are facing, particularly when it comes to remote working. Here are some of the key points to emerge:
- ‘The State of Remote Work Security 2021’ compiled by Cybersecurity Insiders asked IT professionals about their remote work security concerns. Top of the list came “end user exposure to malware and phishing attempts”, followed by “data protection issues” and “working from unmanaged resources”. However, some of the most revealing findings emerged when respondents were invited to rank the biggest security challenges associated with supporting remote workers. Far and away the most significant challenge (cited by almost 60% of respondents) was “user awareness and training”, followed by concerns over “home/public Wi-Fi network security” and “sensitive data leaving the perimeter”
- Research from Breaming found that the number of cyber-attacks launched against UK businesses surged as the country went into Covid lockdown last year, and has remained at exceptionally high levels ever since. In fact commercial cyberattacks on UK businesses are up 11% year-on-year to nearly 2,000 per day in the first quarter of 2021. A spokesperson from Breaming said “The mass move to home and hybrid working means that company data and IT systems are now being accessed via a wide range of personal equipment on unmanaged domestic internet connections. Each offers a potential point of failure for hackers to gain access to company systems over the public internet, and hackers are doubling down to take advantage of vulnerabilities created by this fundamentally less secure way of working”
- Meanwhile a new report from McAfee confirmed that the second half of 2020 had been tough for cybersecurity teams everywhere. The figures show that an average organisation received 588 threats a minute in the third quarter of 2020, up 40% on the previous quarter. The final quarter of the year was even worse, reaching 648 threats per minute, up an additional 10% on quarter 3. Mobile malware has seen some of the highest growth, rising 118% on the previous quarter. And the cloud is also an increasingly popular target for criminals, as indicated by the 3.1 million external attacks on cloud user accounts
- A report from Unit42, the cybersecurity branch of Palo Alto Networks claims that phishing attacks are becoming even more dangerous as they grow in scale and become harder to detect. The most popular phishing tactic, used in almost four out of ten attempts, is the fake CAPTCHA, in which users are asked to verify themselves through a fake CAPTCHA script. Instead of an actual script, the .PDF contains a clickable image, sending the victim to a malicious domain
- Finally, the ‘2021 Cloud Data Security Report’, issued by cloud security company Netwrix found that a lack of in-house security knowledge was one of the primary reasons why financial organisations suffered high numbers of cybersecurity incidents last year. Polling 937 IT professionals worldwide, Netwrix found that more than half (59%) of financial organisations see understaffed IT and security teams as the number one reason for their cloud security problems. Other major factors include lack of expertise in cloud security and employee negligence
What is clearly emerging from these studies is a picture of organisations battling against growing threats to their data, coming primarily in the form of phishing attacks, targeted attacks on cloud infrastructure and ransomware. And the increasing popularity of hybrid and remote working practices only serves to heighten many of these problems.
On the other side of the coin, we have a growing skills gap in the cybersecurity industry, with insufficient numbers of security professionals being ever-more stretched, as they face daily battles to protect their organisations from both outsider and insider threats.