In recent years, three interconnected trends have gained momentum: remaining competitive in a rapidly changing business world, safeguarding against intensifying cyber risks, and achieving both objectives while simplifying and digitally evolving.
As hybrid work models become more widespread, company networks are growing increasingly scattered, intricate, and undefined. To control risk in this highly connected virtual environment, cybersecurity strategies are topping the agendas of many boards. While fundamental measures like multi-factor authentication (MFA) and software patching remain vital, relying solely on a perimeter-focused security approach is no longer sufficient. Organisations can instead mitigate the consequences of mounting security threats by adopting a resilience-centred mindset. Here are four keys to achieving cyber resilience.
1. Embrace vulnerability as a fact of hybrid work and move to resilience
The emergence of hybrid work has pushed companies across various industries to adopt cloud technology, effectively eradicating the concept of a well-defined perimeter. Work is now conducted in hard-to-secure areas – across multiple platforms, cloud applications, personal devices, and home networks.
However, as we all know hybrid work is here to stay, and so even if securing networks is more complex than ever before, it’s important for security leaders to acknowledge vulnerability as an inherent part of the hybrid work landscape and find ways to reduce the business impact of potential attacks.
What security leaders can do: Work with cloud specialists. Securing cloud environments is very different to protecting internal networks. It involves different rules and stakes. Since the primary cloud vulnerabilities stem from administrative errors, such as misconfiguration and inconsistent security policy enforcement, make sure you partner with specialists who understand both security and cloud systems. From a digital forensics perspective, it’s also crucial to regularly audit your entire system to ensure you identify any vulnerabilities.
2. Limit how far ransomware attackers can get in your system
With networks expanding across the cloud multiverse, it’s only natural that ransomware attacks are intensifying – and they are costing companies billions. In 2021, ransomware inflicted an estimated US$20 billion in damages; by 2031, this figure is projected to surpass US$265 billion, according to Cybersecurity Ventures’ 2022 Cybersecurity Almanac. The Ponemon Institute’s Cost of a Data Breach Report 2021 reveals that the average expense of a ransomware attack is US$4.62 million (including escalation, notification, lost business, and response costs, but excluding the ransom). South Africa is far from immune to these attacks, or how much they cost. According to the Veeam Data Protection Trends Report 2022, 86% of South African organisations interviewed (or 9 out of 10 businesses) suffered ransomware attacks in 2022, making cyberattacks one of the single biggest causes for downtime for the second consecutive year. According to the data we have gathered at Cyanre, the average ransom in South Africa is around R6 million, although the highest ransom demand we saw in 2021 was for R88 million.
Financial costs only represent part of the picture. Ransomware attacks lead to significant operational downtime, sensitive data exposure, and reputational harm. The skyrocketing prevalence of ‘ransomware as a service’ is driving this trend. Evolving cybercrime supply chains allow cybercriminals to purchase effective cybercrime kits and services for as little as US$66. These affordable kits provide opportunistic criminals with better tools and automation to scale their operations, enhance the sophistication of their attacks, and reduce costs. As a result, the economic factors behind successful ransomware attacks are accelerating their rapid growth.
What security leaders can do: Implement Zero Trust principles. Ransomware attacks primarily use three entry points: remote desktop protocol (RDP) brute force, vulnerable internet-facing systems, and phishing. Organisations can minimise potential damage by forcing attackers to exert more effort to access multiple critical business systems. Establishing least-privilege access and adopting Zero Trust principles can stop attackers from moving laterally through systems if they do manage to find a vulnerability to breach. This is another reason why it’s so key to conduct a digital forensics audit if there is even a minor breach into your network – cybercriminals will often wait patiently in a system until they can tease out more vulnerabilities and eventually access sensitive data. The only way to ensure a network is completely secure after a breach is through digital forensics.
3. Elevate cybersecurity into a strategic business function
In the current security threat landscape, knowledge is a powerful asset. The value of a robust security posture lies in understanding the threat landscape and prioritising resilience, rather than solely focusing on preventing individual attacks.
What security leaders can do: Evaluate your Zero Trust approach. A resilient security posture transforms security from a protective service into a strategic business enabler. A proactive security approach facilitates hybrid work, enhances customer experience and trust, and fosters innovation. Adopting Zero Trust is essential for resilience.
4. Implement the fundamentals of security
As staff and budgets become increasingly strained, it’s crucial for security leaders to manage risk and establish the right priorities. Almost all cyberattacks could be prevented by enabling multifactor authentication (MFA), implementing least privilege access, updating software, installing anti-malware, and safeguarding data. However, the adoption of strong identity authentication remains low.
What security leaders can do: Having secure identity protections, whether it’s MFA, password-less, or other defences like conditional access policies, minimises the opportunity for cybercriminals to breach systems. Unfortunately, one of the biggest issues we come across, when our digital forensics experts are brought in to investigate a business email compromise (BEC) breaches, is that companies do not have the minimum requirements enabled in their email environments, or they are on the incorrect subscription package for their needs. When this happens, we are not able identify which side was compromised. The minimum requirements are:
- 30 to 90-day audit log retention period
- Microsoft 365 Business Standard
- Microsoft Azure P1
Why does this happen? Often, businesses do not even realise that they have email vulnerabilities. An external IT vendor migrates the business to Microsoft 365, but the setup of audit logs is not completed. In addition, no rules were created to prevent users from creating their own forwarding rules or to alert IT personnel of the creation of these rules. Two-factor or multi-factor authentication is also left unenabled, which means users are not aware of perpetrators accessing their account. These are simple yet powerful tools that should be basic cybersecurity hygiene factors.
The journey to cyber resilience
We are currently in a time of transition. As organisations have increasingly relied on workplace flexibility and fast-tracked their digital transformation, they have become more susceptible to new and more serious attacks. The perimeter has grown and become more hybrid, encompassing multiple clouds and platforms. While new technologies have greatly benefited many businesses allowing for productivity and growth even in challenging times, these shifts have also provided an opportunity for cybercriminals to exploit vulnerabilities within increasingly complex digital environments. To achieve resilience in the face of attacks, it’s time to practice good cyber hygiene, implement architectures that supports Zero Trust principles, and integrate cyber risk management into your business operations.