Site navigation

Hackers Delight: Report Shows Most Cyber Security Still Sucks!

Ross Kelly

,

recaptcha

The latest Nuix Black Report has shed light on the significant security flaws found in a host of industries including healthcare and manufacturing. 

According to the latest Nuix Black Report, cyber attackers are able capable of breaching security systems with frightening ease. 71% of cyber attackers claim they could breach an organisations security systems in under ten hours, with industries such as hospitality being particularly open to attack.

The report (found here) is based on a survey of more than 100 cyber incident responders and known hackers from 16 countries, revealing their attack methods, favourite exploits and what countermeasures they have found to be the most and least effective.

The report highlights the lax nature of cybersecurity within organisations across a host of industries and provides a damning insight into the culture, practices and negligence of companies when dealing with cyber threats.

Simple, Preventable, Stupid

Nuix state in their report that “when you read about data breaches in the media, the victims usually claim they suffered an unprecedented and highly sophisticated cyber attack”. However, they refute these claims by highlighting that these incidents are often avoidable, saying “much later, it emerges that someone forgot to apply a security patch, or something equally simple and preventable.”

In an increasingly dangerous digital environment, why are companies continuing to implement lax security procedures, leaving themselves open to attack and their customers’ data at risk?

Blissfully Unaware

Some 60% of hackers that Nuix spoke to said it was a rarity for them to encounter security systems that they had difficulty breaking into, with 93% also saying that their targets do not even detect attacks more than half the time. Within these frightening statistics, 75% said they were rarely detected by their victims after an attack and 2% claimed they weren’t even detected at all.

Hackers appear to be unimpressed by organisations’ security posture and claim that most security professionals do not understand what to look for when detecting breaches. In regards to countermeasures, 34% of respondents said that host system hardening poses the greatest challenge to breaking entry. 18% said intrusion detection and prevention systems posed a serious challenge, while 14% highlighted endpoint security.

Honeypots and other deception technologies accounted for 10% of the survey share.

Firewalls (5%) and user access controls (3%) were some of the least challenging defence mechanisms hackers encountered; additionally, a meagre 8% said Microsoft’s Enhanced Mitigation Experience Toolkit and antivirus software was challenging – Raising serious questions for both businesses and households.

The report says that once attackers have breached the perimeter, they can operate with ease to map out target environments and find exactly what they are looking for. Once they have achieved their goal, hackers said they are capable of covering their tracks in less than 30 minutes – In and out before anyone can blink an eye.

Vulnerable Sectors

Every industry must be conscious of their data security in 2018. With such sensitive information being held across a range of sectors from retail to healthcare or hospitality, the need for robust cybersecurity is essential.

Despite this, the report details extensively how a number of sectors are viewed by cyber attackers; across all industries, the majority of respondents (54%) said they could find their target data in under five hours. The industries deemed easiest to attack by respondents are as follows:

  • Food and Beverage
  • Hospitality
  • Retail
  • Law firms
  • Manufacturers
  • Sports and entertainment companies
  • Hospitals and healthcare organisations

The worst ranked industries were; hospitality, food & beverage and retail. 33% of respondents claimed they could find the data they wanted from hospitality organisations within an hour, with 30% being able to do the same with retail.

Alarmingly, 38% claimed they could do this with ease against hospitals or healthcare organisations; indicating a significant lack of robust cybersecurity and protection of sensitive medical data. The NHS was rocked last year by the WannaCry ransomware attack which brought gridlock to a number of NHS trusts across the country.

Scottish Cybersecurity Forum, 25/04/2018, Murrayfield Edinburgh

Threat Vectors

The favoured method of attack by hackers appears to be network attacks, with 28% identifying it as their go-to method. However, social engineering ranks in second place with 27% of the share. Social engineering is an extremely popular and common attack method, and can be used to devastating effects; social media is beginning to play an enormous role in social engineering as attackers look to lull victims into a false sense of security before scarpering off.

17% said they always used social engineering to obtain information about a target, while 71% saying they use it ‘sometimes’ or ‘often’ – Only 12% said they never use it, a clear glimpse into the popularity of this attack method.

Deeper into the social engineering figures we find specific methods such as phishing, physical social engineering and phone-based methods. The overwhelming majority (62%) said phishing is their favourite type of social engineering attack.

Testing, Testing…

Organisations know the risks of maintaining substandard security measures, however many continue to do so, the report says. Penetration testing is an efficient method through which to test the strength of any cybersecurity measures, however according to the report only 7% of clients remediate all vulnerabilities and then re-test to see if they have plugged the gaps.

33% of respondents believe that businesses only have to deal with security for compliance reasons, and nothing more. 19% claimed that organisations were of the opinion that “companies get hacked every day, we should do enough to show we think it’s important, but no more.”

This lax attitude toward cyber security is a cultural aspect of business that Gerry Grant, Chief Ethical Hacker at Curious Frank (Scottish Business Resilience Centre), believes needs to be addressed. He said: “often it is seen as a box ticking exercise or due to audit requirements.”

This cannot be allowed to continue when one considers how critical data is to our daily lives, with Gerry saying “it’s people’s lives they’re playing with.”

Ensuring that basic preventative measures are taken is essential and Gerry was keen to point out that in the event of breach, organisations often only focus on the “obvious, critical vulnerabilities” and “focus on the easy stuff” – However this doesn’t always address the problem fully, and he insists that often hackers will come back upon discovering more blatant security flaws.

Part of the problem, he believes, could be addressed by promoting solid cyber hygiene, saying he is a “strong believer in teaching users good cyber hygiene at work and at home”. From the board of directors to administration staff, cyber hygiene must be instilled in the minds of staff.

Look to the Future

According to respondents, the most concerning cybersecurity threats organisations will face in the future will be mobile attacks, ransomware biomedical device hacking and, as testing continues on the use of autonomous vehicles, hackers will look to attacking vehicle devices; actions which could irrevocably damage the lives of commuters.

Organisations have to take responsibility for their cybersecurity, else risking critical data breaches in the future. In addition to this, encouraging individual responsibility in their workforce must be acknowledged.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data