Cyber security trends, what’s changed from 2020 to now?
At the start of 2020, cyber security trend experts warned that cloud security needed greater focus, that ransomware would become more targeted and sophisticated, and that cyber criminals were exploiting artificial intelligence (AI). Experts also estimated that technological advances such as 5G would cause some security headaches, and that the widespread use of IOT devices would signal new and increasingly complex cyber security threats. Predictions were that phishing would remain the biggest thorn in the side of cyber security, mobile malware would become a much bigger problem, and that insider threats arising from the malicious or negligent use of systems by employees would continue causing sleepless nights.
They weren’t wrong, especially about ransomware becoming more prevalent and targeted. Several ransomware groups targeted banks across the globe in 2021, increasing the ransom amounts they demanded in exchange for not publishing stolen data. According to Kaspersky, it is no longer about encrypting data but about disclosing sensitive information stolen from victims' networks. Due to payment card industry security and other regulations, these leaks can result in major financial losses.(1)
Data breaches were also among the leading cyber security trends in the healthcare industry, with sensitive information about businesses, employees and patients remaining a target of cyber criminals. The healthcare sector is now the most targeted industry in the world, with 66% of companies reporting ransomware attacks in 2020, which is an increase of around 22% to the previous year’s survey by Check Point Research.(2) Among these was the Life Health Care group, which suffered an attack that forced it to shut down systems and impacted its operations for almost two months.(3)
Law firms, too, were under fire, and it wasn’t only the large firms. Companies with less than 20 lawyers accounted for half of all ransomware attacks in the legal industry.(4) Though ransomware played havoc, phishing, as the experts predicted, was the most common cyber attack experienced by businesses in 2020.
But, what nobody predicted was the COVID-19 pandemic, causing a 300% increase in remote working and compounding an already complex threat landscape.(5) In many cases, employees were mobilised to work remotely so quickly that organisations didn’t have the time to really consider the implications for information security. Security controls and protocols were neglected because the main goal was to keep the business cogs turning.
Fast forward to March 2021, and unsurprisingly, experts are predicting an increase in attacks on remote infrastructure, as well as large-scale failures arising from the growing use of multiple, connected cloud architectures.
Citing a survey by Enterprise Technology Research, Charl Ueckermann, Group CEO at AVeS Cyber International, says the percentage of workers permanently working from home is expected to double in 2021.(6)
“The level and complexity of cyber security threats associated with the sheer number of people working remotely present an unprecedented challenge for organisations. While ransomware, phishing and cloud vulnerabilities are ever-present threats to be watched and managed, securing the remote workforce is undoubtedly the number one concern now. A rethink about how data is protected in a hybrid and converged data world is absolutely necessary. Cyber security strategies need to be realigned to be data-focused rather than technology-focused.”
Of real concern, says Ueckermann, is how data is accessed and how to secure it effectively. Data is the lifeblood of every business. No business wants the integrity or security of its data to be compromised. The problem is that data is no longer housed centrally and securely in a closed network – it is everywhere. It is on employees’ laptops and mobile phones. It’s in the cloud.
“How secure are these devices? How should these devices connect to sensitive company information? How is sensitive information protected at its source? Is data-level security in place to prevent data loss and fraud? Are users equipped to evade zero-day cyber threats? Are they cyber security aware?
“These are important questions for every company to be able to answer, especially those which store and process sensitive information, such as financial institutions, lawyers, healthcare companies and doctors, and education institutions. The greater the sensitivity of the data, the more valuable it is on the black market.
“Using a ‘pattern of life’ approach, companies need to look at how data flows both inside and outside the organisation. Proactively monitoring behaviours and patterns over time – such as how data is stored, accessed, and shared – is the only way to reduce cyber risks and data costs at the same time.”
So, what are the key cyber security priorities in a remote working world?
“Cyber security awareness training; governance, risk and compliance tools; and fraud detection systems, including identity verification and risk assessments,” concludes Ueckermann.
“As companies fast-track digital transformation, empower more people to work remotely, and increasingly shift to the cloud, an out-of-the-box approach toward technology investments is required. It is not simply about availability. It is about optimising cost, performance and data security.”
(1). Kaspersky. (2020, 11 30). cyberthreats-to-financial-organizations-in-2021. Retrieved from securelist: https://securelist.com/cyberthreats-to-financial-organizations-in-2021/99591/
(2). Latham, D. (2021, 11 09). cyberattackers-increasingly-target-healthcare-and-south-africa-is-not-immune. Retrieved from health-e: https://health-e.org.za/2021/01/09/cyberattackers-increasingly-target-healthcare-and-south-africa-is-not-immune/
(3). Mungadze, S. (2020, 08 31). Life Healthcare reveals damage caused by data breach. Retrieved from ITWeb: https://www.itweb.co.za/content/rW1xLv59YPGvRk6m
(4). Schreider, T. (2020, 05 26). ransomware-attacks-in-the-legal-profession. Retrieved from law.com: https://www.law.com/corpcounsel/2020/05/26/ransomware-attacks-in-the-legal-profession/
(5). Forrester. (2020, 10 30). predictions-2021-remote-work-automation-and-hr-tech-will-flourish. Retrieved from Forbes: https://www.forbes.com/sites/forrester/2020/10/30/predictions-2021-remote-work-automation-and-hr-tech-will-flourish/?sh=452475a32533
(6). Chavez-Dreyfuss, G. (2020, 10 22). us-health-coronavirus-technology/permanently-remote-workers-seen-doubling-in-2021-due-to-pandemic-productivity-survey. Retrieved from reuters: https://www.reuters.com/article/us-health-coronavirus-technology/permanently-remote-workers-seen-doubling-in-2021-due-to-pandemic-productivity-survey-idUSKBN2772P0
AVeS Cyber Security
AVeS Cyber Security forms part of the AVeS Cyber International Group of companies and is a specialist in industry-specific IT Governance & Architectural services, combining expert knowledge and services with leading technology products to provide comprehensive Information Security and Advanced IT Infrastructure solutions. Over the past 23-years, AVeS Cyber Security has strategically honed its solutions and services to help Southern African businesses future-proof their IT environments against the continually evolving threat landscape while achieving their digital transformation aspirations. The company offers a leading portfolio of professional services, products, and training in security, infrastructure, and governance solutions. In 2019 and 2020, the company won eight awards from some of the world’s top technology vendors, indicating competency, strength, innovation and robustness in an industry that is fast growing in complexity due to evolving challenges, such as ransomware, advanced targeted attacks and the Internet of Things. The awards include Kaspersky’s Africa Partner of the Year 2019 and 2020, Kaspersky’s Top META Learning Partner 2020, ESET’s Regional SMB Sales Champion 2019 and 2020, ESET’s Product Champion 2019, Symantec’s SMB Partner of the Year 2019, and Sophos’ Upcoming Partner of the Year 2020. AVeS Cyber Security also received four new partner statuses, namely, Microsoft Gold Datacentre Partner, DellEMC Gold Partner, Veeam Silver partner and Sophos Platinum partner.