5 cybersecurity trends to focus on in 2023

By Professor Danny Myburgh

 

In 2022, ransomware continued to plague organisations across the globe, from threat actors accessing the personal details of millions of South Africans, to IT company Advanced revealing that it had been the victim of a ransomware attack in August 2022. Even though the company quickly reacted to the threat, it wasn’t only its own systems that were disrupted, but those of a major client – the NHS, the UK’s national health provider.

 

Similarly, in October 2022, Australia’s largest health insurance company, Medibank, was breached by ransomware, resulting in the personal details of over 9.7 million customers being exfiltrated.

 

Earlier in the year, Toyota had to cease operations in 14 of its Japanese plants and temporarily shut down factories in Central and North America after multiple Toyota suppliers fell victim to ransomware attacks in February and March.

 

For the past few years, ransomware attacks have been steadily on the rise, accelerating since the Covid-19 pandemic. With no reason to assume these attacks will dip in 2023, let’s see what we can expect to see from the year ahead and which cybersecurity trends business leaders should be focusing on.

 

  1. Cloud credential attacks

One of the biggest shifts within enterprise IT strategies over the past decade has been the adoption of Software-as-a-Service (SaaS) platforms. Hybrid working and work-from-home policies have necessitated this shift, but there is a cyber concern. Many SaaS applications do not integrate with the existing single sign-on (SSO) solutions that organisations have implemented over the years, meaning these security controls are rendered all but useless. SaaS solutions are integral to how organisations work – but they also serve as weaker access points for threat actors looking to infiltrate networks and exfiltrate data.

 

The solution: Implementing multi-factor authentication designed to work with SaaS solutions is a vital element in all cybersecurity strategies.

 

  1. Fifth-generation ransomware

That’s right. We are now in the fifth generation of ransomware. Remember, ransomware is big business, with a handful of large criminal organisations running the show and developing increasingly sophisticated software to target the same organisations over and over again. According to a recent Cybereason report, 55% of businesses fell victim to at least one ransomware attack in 2021. By 2022, this had risen to 73%. We expect to see a similar jump in attacks in 2023.

 

There’s also the very real danger that ransomware will increasingly work to access cloud storage controls. Many organisations accelerated cloud adoption during the pandemic, losing sight of where sensitive data is stored and who has access to it. Many cybersecurity strategies have focused on endpoint access, particularly with so many employees working from home or from their own devices. In response, threat actors are targeting cloud storage through weak credential management. Cloud storage offers significant data protection and flexible recovery options – but any cyber solution is only as secure as the individuals who have access to it.

 

The solution: Regular cyber vulnerability audits are one of the best ways to test current defences and to review where there may be gaps in the network and human behaviours. With ransomware continuously evolving, cybersecurity needs to keep pace.

 

  1. The rise of deepfakes

Cybersecurity professionals have been speaking about social engineering for years, and this became a critical security issue during the pandemic. The continuous education around social engineering has worked however, and many employees and individuals are increasingly wary of SMSs, emails, WhatsApps and suspicious links.

 

This just means that cybercriminals need to find new ways to convince people to click on malicious links – enter the era of deepfakes: highly convincing images and documents that are nevertheless completely fake.

 

The solution: Verify, verify, verify. Continue to educate your employees around verifying data, images and documents before acting on them. Simply picking up the phone and calling the sender of an email can mitigate a disaster. Advanced firewall solutions also remain critical, because they provide organisations with advanced perimeter network security against cyber threats, even when data and workloads are sitting comfortably in the cloud.

 

  1. IT burnout

Between the massive skills shortages in IT and security teams working around the clock to ensure cyber resilience, burnout is having a major impact on the IT and cybersecurity landscape. The challenge is that IT – and particularly cybersecurity – is not a 9 to 5 business. It’s a 24/7, 365 days a year challenge, particularly because threat actors are based around the world and prone to test security vulnerabilities when an organisation is most likely to only have a skeleton staff on shift.

 

The solution: A managed service provider is always on, no matter what time of day or time of the year an attack may occur. Having a digital forensics lab on call 24/7 ensures an organisation can respond and remediate cyber threats quickly and efficiently, even when IT teams are off the clock. It also gives businesses access to top-quality cybersecurity expertise and ensures that organisations are completely compliant with local and international digital and data regulations.

 

  1. Supply chain threats

In 2022, we collated the data from the cyber breaches we had investigated over the past two years. At 8,62%, one of the most worrying findings was the number of victims that were breached through their external IT service provider. Since then, we have seen an uptick in attacks through supply chain partners, culminating in an attack in April 2022 in which hackers gained access to first names, surnames, email addresses and cellphone numbers belonging to more than 3.6 million South Africans. The breach was through a third-party service provider of a large local organisation holding the personal information of millions of South Africans.

 

The solution: Regulations and the requirements of insurance companies mean that organisations need to conduct more dynamic and frequent assessments of their supply chain risk, as well as evaluate the access that third parties have to their networks. The best solution is to partner with a digital forensic expert. At Cyanre, our ability to contain attacks while simultaneously ensuring a full digital, defensible audit trail that can be used in court, will satisfy insurance companies and ensures that all traces of the hackers are removed from a system, identifying and plugging any vulnerabilities.