CyberAttacks cost your Company Money.
???? Mike Holt, CCSP
Cloud Security Specialist - Helping customers address their Cloud Security, Compliance and Risk mitigation Challenges.
What is a cyber-attack?
Let's take a step back and first understand what a cyber-attack is, to do this, let's start with an analogy. Imagine a burglar trying to break into your home. They may try to pick the lock, break a window, pretend to be someone they're not, or simply walk in through an unlocked door.
Similarly, cyber-attackers use various tactics to gain access to computer systems. For example, they might use an SQL injection instead of picking a lock or try to brute-force your password instead of breaking a window. Phishing attacks can be compared to impersonating a delivery driver, while leaving your devices unsecured is like leaving an unlocked door.
Once a burglar breaks into your home, they can do all sorts of damage, such as, steal valuable items or vandalise your property. Similarly, once a cyber-attacker gains access to a computer system, they may steal sensitive data, corrupt files, install malware, or cause other damage.
Your next question may be “Companies secure their buildings from burglars why don’t they apply the same logic and secure their digital assets from cyber-attackers?”
The need to keep our belongings safe is deeply ingrained in human nature. For thousands of years, we have used locks and keys to secure our homes, valuables, and possessions.
The first lock and key devices were discovered in Nineveh, the ancient capital of Assyria (modern-day Northern Iraq and South Eastern Turkey), more than 6,000 years ago! Since then, locks have evolved, with wooden pin locks developed by the Egyptians being one of the earliest iterations of the modern lock. These locks used a key to lift the pins from the bolt holes, allowing the bolt to move and providing security against unwanted access.
In today's digital age, the need to protect our assets has shifted from physical locks to cybersecurity measures. Companies must apply the same logic of protecting physical assets to their digital assets and implement appropriate cybersecurity measures to safeguard their systems and data from cyber-attacks.
Ancient locks evolved gradually over the centuries, cybersecurity measures on the other hand, must evolve rapidly to keep up with changing threats and technologies.
Many organisations struggle to keep up with the constantly evolving landscape of cybersecurity and the new challenges it presents. As a result, we often hear about organisations in the media that have fallen victim to data breaches or hacks. Here’s more detail why:
Cyber-attacks are becoming more frequent and more costly
In the Fortinet 2023 Cybersecurity Skills Gap Global Research Report, responses were obtained from online interviews and email surveys of 1,855 IT and cybersecurity decision-makers in 29 countries, from a range of businesses with 100-5000 employees. The findings indicated breaches had risen between 2021 and 2022.
84% of respondents indicate their organisation experienced one or more breaches in the past 12 months, up from 80% the year before.
There was a notable increase in the cost of breaches exceeding $1 million.
Nearly half (48%) of organisations that suffered at least one breach in the past 12 months indicate that it cost more than $1 million to remediate, up from 38% in 2021.
Of the surveyed companies in the Fortinet report, phishing was the most common attack method.
Reference: Fortinet 2023 Cybersecurity Skills Gap Global Research Report
According to IBM’s 2022 Data breach annual report, the global average cost of a data breach in 2022 is $4.35M! Key notes from that report are:
What’s at stake?
Cyberattacks can wreak havoc on organisations of all types and sizes. Depending on the nature of the business, the effects of a successful cyberattack can range from a minor inconvenience such as your favourite digital news site being temporarily offline to more serious consequences like putting lives at risk if critical infrastructure, such as power grids or transportation systems, are attacked.
领英推荐
It’s important to note that small businesses are far from immune, whilst they might not possess the volume of valuable information of their large counterparts, they often lack the resources to recover from an attack.
Here are the key areas that are at stake in the event of a cyber-attack:
Cyber-attacks have far-reaching consequences that go beyond financial costs and can impact societies, individuals, and organisations in various ways. Let's explore some real-world examples of cyber-attacks and their costs, including financial, non-financial, and societal impacts.
The financial costs of a cyber-attack
To understand just how bad it can get, let’s look at the well-known hack in 2017 to US-based credit bureau, Equifax. This remains as one of most expensive in history where private records of 147.9 million Americans, 15.2 million British citizens, and around 19,000 Canadians were compromised. Hackers took advantage of the company’s failure to update the Apache Struts system and gained access via a known vulnerability that was patched months earlier.
In the aftermath, Equifax was criticised for its network design, encryption, and data breach mechanisms. Had they kept their software up to date, perhaps they could have avoided the titanic financial impact of this breach. All told, this cyber-attack cost Equifax a mind boggling US 2 billion dollars! This figure consisted of settlement costs and free credit monitoring to affected users.
The non-financial costs of a cyber-attack
Whilst a cyber-attack can cost an absorbent sum of money to remediate, an attack can have more than just financial consequences.
The Facebook-Cambridge Analytica scandal was a data privacy controversy involving the social media giant Facebook and the British political consulting firm Cambridge Analytica. It was not a cyber-attack in the traditional sense of the term but rather a data breach that occurred due to the misuse of Facebook user data by Cambridge Analytica.
In 2014, Cambridge Analytica obtained access to the personal data of millions of Facebook users without their consent, through a third-party app that collected user data.
The allegation is that the data was used to create psychographic profiles of voters. These profiles were then used to target individuals with specific political ads and messages, aimed at influencing their voting behaviour during the 2016 US presidential election in favour of Donald Trump.
The Facebook-Cambridge Analytica scandal highlights how a breach with non-financial motivations can still be extremely impactful.
The scandal led to investigations, fines, and changes in data privacy regulations, as well as increased scrutiny of Facebook's data collection practices.
The societal cost of a cyber-attack
The damage a cyber-attack can cause has the potential to extend far beyond the immediate victim or company. Take the WannaCry ransomware attack in May 2017 for example. This attack affected over 300,000 computers across 150 countries.
The attack exploited a vulnerability in Microsoft's Windows operating system, which was identified by the US National Security Agency (NSA) and was subsequently leaked by a group of hackers known as Shadow Brokers.
The attackers demanded a ransom of $300 in Bitcoin per infected computer, which was later increased to $600, with the threat of permanently locking the victim's files if the ransom was not paid within a certain timeframe. Here is an in-depth breakdown compiled by the US Government Cybersecurity & Infrastructure Security Agency (CISA).
Critical infrastructure systems were heavily impacted which translated to people across the globe being negatively affected. Here are a few examples of how:
How can an organisation reduce the cost of a cyber-attack?
Conclusion
The bottom line is this: cyber-attacks are costing more, becoming more prevalent and they're not going away anytime soon. But don't despair – there are things you can do to protect your organisation and minimise the risk of a cyber-attack.
The good news is that by investing in prevention and mitigation measures, including regular cybersecurity training, incident response planning, and adopting a zero-trust policy, organisations can significantly reduce their risk of a cyber-attack and avoid the potentially devastating financial and reputational consequences that come with it.
Remember, no matter the size of your business, cybersecurity should always be a top priority. So, stay vigilant, stay safe, and don't let the bad guys win!