{"id":60623,"date":"2021-11-29T09:30:00","date_gmt":"2021-11-29T09:30:00","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=60623"},"modified":"2023-05-25T11:31:04","modified_gmt":"2023-05-25T10:31:04","slug":"prepare-defend-recover-repeat-the-vicious-cybersecurity-cycle-in-2021","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2021\/11\/29\/prepare-defend-recover-repeat-the-vicious-cybersecurity-cycle-in-2021\/","title":{"rendered":"Prepare, defend, recover, repeat \u2013 The vicious cybersecurity cycle in 2021"},"content":{"rendered":"\n<p><em>It&#8217;s fair to say that 2021 has been one of the most challenging years on record for business leaders and their organisations.<\/em> <em>Ed Williams, EMEA Director of SpiderLabs, Trustwave<\/em>, <em>reflects on the past 12 months and suggests how we can move forward with strong cyber hygiene in place.<\/em><\/p>\n\n\n\n<p>2021 has been a year of significant change for cybersecurity \u2013 but that\u2019s the nature of the industry. It\u2019s fast-paced, increasingly advanced, and can be relied upon to throw challenges in the face of organisations when they least expect it.<\/p>\n\n\n\n<p>The one constant is that everything will continue to change. Businesses are tackling new threats, the annual spend on defence solutions is increasing and more people are having those all-important initial conversations about cybersecurity. But there is still a long way to go. While we are seeing more people talk about cybersecurity strategies, and even getting to the stage of planning the next phase, it often ends up with leaders choosing the bare minimum option \u2013 mostly due to budget restrictions. Given that investment in cyber solutions offers no immediate RoI, it\u2019s important that leaders act with foresight to get ahead and continue on their maturity journey in order to limit the impact.<\/p>\n\n\n\n<p>Businesses know all too well the devastating repercussions of a successful attack, and most would agree that a post-attack budget is far larger than a pre-attack one. Suddenly, once the perimeter has been breached, companies are much more convinced by greater security measures, but by this point it\u2019s already too late.<\/p>\n\n\n\n<p>The past year has witnessed a great many cyberattacks, but two major threats to modern businesses are ransomware and insecure supply chains.<\/p>\n\n\n\n<p><strong>Responding to ransomware<\/strong><\/p>\n\n\n\n<p>Throughout 2021, ransomware has become more sophisticated and prominent in cyberattacks. Advances in this threat vector means a single breach can leave organisations trembling in its wake as systems and data become compromised. The main question being asked by clients now is: how can we get in front of ransomware? And to answer that question, we must break down the life cycle of ransomware to understand how it enters the network. It\u2019s usually down to phishing, password guessing, exploitation of vulnerabilities, or malicious documents in an email. Once they understand the entry point for ransomware, businesses can start putting together a strategy to safeguard against it.<\/p>\n\n\n\n<p>Vulnerability assessments are a critical part of getting ahead of attackers. While most businesses already conduct some form of assessment, it\u2019s not always at the necessary scale or depth. Penetration testers often get these responses from business teams following an assessment: \u2018I don\u2019t know what that is\u2019, or \u2018I thought we had turned that off&#8217;. It can be difficult to achieve good asset management across a complex network environment, especially in large organisations. So, as a bare minimum, businesses should remember the key basics that can really make a difference: patching, passwords and policies.<\/p>\n\n\n\n<p>Part of the issue when it comes to tackling ransomware is that it\u2019s far too easy to become distracted by the new shiny tech being released \u2013 such as Artificial Intelligence and Machine Learning \u2013 and forget about fundamental cyber hygiene. In order to get in front of ransomware, it\u2019s time to ditch the buzzwords and reinstate those strong foundations. It is always worth hammering home the basics \u2013 not because they\u2019re easy, but because they\u2019re needed.<\/p>\n\n\n\n<p><strong>The complexity of supply chains<\/strong><\/p>\n\n\n\n<p>Not only has ransomware been an exponential threat this year, but some of the biggest cyberattacks to have taken place in 2021 have had links to the supply chain. From the Colonial Pipeline attack to multiple attempts on the COVID vaccine, supply chains have acted as catalysts for criminals. And the ongoing shift to hybrid working has exacerbated the issue. Transferring resources from legacy technology to the cloud, and leaving connections unprotected, have all widened the supply chain attack surface.<\/p>\n\n\n\n<p>Securing an entire chain of businesses is far more complex than addressing just one individual company \u2013 the number of resources shared and the high level of collaboration that takes place adds to the challenge. Again, it all comes down to best practice and re-establishing the fundamentals. Businesses should carry out regular penetration tests and red teaming exercises, as well as ensuring strong cyber hygiene across the company. In addition, being part of a supply chain demands a certain amount of honesty. Each business must be open to discussing their security strategies to guarantee alignment throughout the chain.<\/p>\n\n\n\n<p><strong>A rise in awareness<\/strong><\/p>\n\n\n\n<p>A definite silver lining to 2021 is that awareness of cybersecurity has shot through the roof. Penetration testers are busier than ever, demonstrating that more businesses are starting to appreciate the value in vulnerability assessment and are taking the first step to improving their security. However, as with most things in life, there is always more that can be done. Conducting a pen test is one thing, but acting upon the results is another. It often comes down to budget, but as we\u2019ve already established, the value of spend before an attack greatly outweighs the value after.<\/p>\n\n\n\n<p>Unfortunately, the nature of cybersecurity means we will never reach a point of being 100% secure \u2013 there is always a new threat vector waiting around the corner, or a new attack kit being deployed. Security teams are essentially partaking in a long-term dance with criminals \u2013 sometimes taking two steps forward, or two steps back \u2013 but always alongside each other. As an industry, we need to break this hold and move out in front of the adversaries.<\/p>\n\n\n\n<p><strong>The security resolution<\/strong><\/p>\n\n\n\n<p>So, as we approach 2022, it\u2019s important to set out the security priorities based on what we\u2019ve learned from the last year. Ransomware will get more sophisticated and supply chains will become more complex, so the next phase in security must be based on prevention. Like the Mike Tyson saying: \u2018Everyone has a plan until they get punched in the mouth&#8217;. Rather than plan for what happens when the punch arrives, take the proactive decision to step out of the ring.<\/p>\n\n\n\n<p>2021 has taught us that complexity is the enemy of security. If processes are too complicated, they become far harder to protect. Our security resolution should start with reducing this complexity where possible and taking the necessary time to do it properly. Patching, for example, is ineffective if the business prioritises a quick fix rather than finding the root cause of the vulnerability. This is particularly important for legacy technology. It\u2019s understandable that not all businesses can afford to replace all their legacy solutions with modern alternatives, but they mustn\u2019t be neglected.<\/p>\n\n\n\n<p>Every member of an organisation is now responsible for cybersecurity. To pull away from the horde of cybercriminals banging against the walls of our network perimeters, we must work as units and continue to strive for the next phase in our security development. Moving into 2022, our security resolution must encompass the following: cyber hygiene fundamentals, a decrease in complexity and a preventative approach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s fair to say that 2021 has been one of the most challenging years on record for business leaders and their organisations. Ed Williams, EMEA Director of SpiderLabs, Trustwave, reflects on the past 12 months and suggests how we can move forward with strong cyber hygiene in place. 2021 has been a year of significant [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":60682,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,1489,13,13207,93,24],"tags":[6424,1268,16686,6539,16687],"class_list":["post-60623","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-main-story-newsletter","category-thought-leadership","category-top-stories","category-used","tag-cyber-hygiene","tag-ransomware","tag-spiderlabs","tag-supply-chain","tag-trustwave"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/60623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=60623"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/60623\/revisions"}],"predecessor-version":[{"id":61292,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/60623\/revisions\/61292"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/60682"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=60623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=60623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=60623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}