Building Resilience In A Changing Cyber Threat Landscape

It’s no secret that cyberattacks are a major threat to organisations in all industries. But despite widespread warnings of malicious activity and the disastrous financial and reputational consequences they can cause, organisations are still less prepared for cyberattacks than they realise.

The goalposts are constantly shifting, with technologies like AI accelerating social engineering attacks and bad actors now exploiting cloud servers to conduct their campaigns. On a seemingly endless treadmill of threats, staying ahead can feel like an uphill battle. 

A Constantly Changing Cyberscape

Today, organisations need to be wary of all kinds of attacks, including phishing, malware, and DDoS, to name just a few. One of the most prevalent threats is ransomware attacks, which can lead to the data of millions of individuals being stolen, not to mention that paid ransoms fund cybercriminals and their future activity. 

A recent IDC report commissioned by Kyndryl found that 70% of IT leaders had been successfully targeted by ransomware within the last year, with two thirds choosing to pay the ransom. 90% of those hit by ransomware said that the attacks exfiltrated company data, likely causing company disruption and financial damages.

A lot of these incidents can be traced back to a single staff member or user clicking on a malicious link. An extreme example of the consequences of human error is the data breach of the Police Service of Northern Ireland (PSNI) last year, which shared the personal details of all PSNI staff, resulting in a fine of £750,000.

The pervasiveness of ransomware attacks signals a need for digital forensics teams to be more powerful and efficient in their response. But siloed, disjointed incident response and incident recovery processes often cause further problems and hinder businesses’ ability to get back up and running after an incident, with the two teams often unintentionally working at cross-purposes. 

New Avenues For Attack

Now, cybercriminals have a new tool at their disposal: generative AI. Generative AI can produce audio and video clips impersonating real customers and executives, making it easier to fool security systems and conduct phishing or social engineering attacks. Additionally, criminal groups are using generative AI technologies to spread malware and constantly change its code, meaning it can evade IT security systems easier.

With AI likely to increase the volume and impact of cyberattacks over the next few years, businesses need to start fighting fire with fire. Without harnessing AI and machine learning for themselves to spot patterns and flag anomalies, organisations will simply be unable to adapt their cyber defences to meet this rise in threats. 

When starting to implement AI-driven defences, CIOs need to begin by validating essential control implementation, before stress testing their response and recovery capabilities, and adapting training and awareness programmes to reflect AI-based cyberthreats.

Building Cyber Resilience

Human error and AI are key challenges concerning CISOs, and businesses need to go beyond just predicting when the next attack will hit. To anticipate, protect against, withstand, and recover from diverse cyberattacks, the focus should be on building cyber resilience. But cyber resilience isn’t just investing in the right technologies, it also involves a shift in mindset, where an organisation comes together to see cybersecurity in a more holistic way.

The first step in establishing cyber resilience is identifying the critical services the business is dependent on and importantly with what impact tolerances for data loss and outage. Then, they should map their infrastructure to applications and assess whether the controls already in place can protect against a disruptive attack, detect any future threats, and recover if incidents escalate. Lastly, businesses should outline a customised roadmap for continually improving resilience and modernising infrastructure to continue building resilience, recoverability of their critical service should become an important functional requirement. Once companies have followed these steps, they can consider areas where third-party help or technical expertise might be needed, particularly in sector-specific applications. With a continual focus on cybersecurity and potential attacks, businesses can build a culture of healthy scepticism, reducing the likelihood of a successful attack or human error incident, like that of the PSNI. 

Cyberthreats have always evolved to utilise the latest technological advancements. But generative AI’s unprecedented ability to streamline and speed up malicious activity has facilitated the need for more robust and holistic defences.

For businesses to adapt, they need to arm themselves with AI-enabled defences that are stronger than AI-enabled threats, all while adopting a cyber resilience approach that combines cybersecurity, business continuity, and disaster recovery to minimise disruptive, expensive cyberattacks. 

Duncan Bradley is Practice Leader for Security and Resiliency, Kyndryl UK&I

Image: @Kyndryl

You Might Also Read: 

Ransomware: Businesses Are Well Equipped But Underprepared:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Millions Of US Voters Exposed Online
A Brief History Of Cyber Crime [extract] »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Voyager Networks

Voyager Networks

Voyager Networks is an IT solutions business with a focus on Enterprise Networks, Security and Collaborative Communications.

Silent Breach

Silent Breach

Silent Breach specializes in network security and digital asset protection. Services include Pentesting, Security Assessments, Incident Detection & Response, Governance Risk & Compliance.

Centurion Information Security

Centurion Information Security

Centurion Information Security is a consulting firm based in Singapore that specialises in penetration testing and security assessment services.

Lepide

Lepide

LepideAuditor is a powerful Data Security Platform that enables you to reduce risk, prevent data breaches and prove regulatory compliance.

KOVRR

KOVRR

Kovrr financially quantifies cyber risk on demand. Our technology enables decision makers to seamlessly drive actionable cyber risk management decisions.

Velta Technology

Velta Technology

Velta Technology provide digital safety and cybersecurity solutions for the industrial space.

ScorpionShield

ScorpionShield

ScorpionShield CyberSecurity is an EC-Council Accredited Training Center, and an On-Demand Service for Cybersecurity professionals.

AlJammaz Technologies

AlJammaz Technologies

AlJammaz Technologies is the leading Technology Value-Added Distributor, which distributes advanced technology products, solutions and services in area including networking and cybersecurity.

FREE eBook: Practical Guide To Optimizing Your Cloud Deployments

FREE eBook: Practical Guide To Optimizing Your Cloud Deployments

AWS Marketplace eBook: Optimizing your cloud deployments to accelerate cloud activities, reduce costs, and improve customer experience.

WhizHack Technologies

WhizHack Technologies

WhizHack's mission is to not only create a pipeline of cyber security products but also to empower people to sustainable innovation in securing digital assets of tomorrow.

Certcube Labs

Certcube Labs

Certcube Labs provide a broad range of services in the areas of Assessments, Development, Risk Advisory, Blockchain, Forensics Investigations, Managed Security Solutions, and IT Security Trainings.

Third Wave Innovations

Third Wave Innovations

Third Wave Innovations (formerly RCS Secure) offers a full spectrum of cybersecurity safeguards and IT services.

AuditBoard

AuditBoard

AuditBoard is the leading cloud-based platform transforming audit, risk, ESG, and InfoSec management.

Ark Infotech

Ark Infotech

Ark Infotech is a provider of cloud management services, selective support services, and technology solutions.

Triam Security

Triam Security

Triam Security are on a mission to make software supply chain security effortless, effective, and invisible - so developers can move fast without leaving security behind.

Lumenir Cybersecurity

Lumenir Cybersecurity

Lumenir is the cybersecurity solution developed by Laminar, an Australian IT and communications company with a long history of supporting critical industries across the country.