In a world with ever-shifting threats on a personal, professional, and even national scale, cybersecurity professionals scrape and fight just to keep up with adversaries.
Advancements in technology like AI have made it easier for bad actors to create more sophisticated social engineering attack vectors, and even generate pernicious malware.
Digital transformation, the rapid adoption of cloud technologies, and the growing presence of IoT devices, is also doing its part in exacerbating the situation.
Cyber-criminals are staking their war on every front, relying on old methods of email phishing with updated techniques, to exploiting connected devices left unsecure in the age of hybrid work.
The Burden of Cybersecurity is Only Getting Heavier
Katie Ralph, director of solutions engineering EMEA at SonicWall, began her talk at Dynamic Earth highlighting the cacophony of alarm bells cybersecurity specialists deal with on a daily basis.
CISOs, CIOs, CTOs, and IT managers are “constantly baffled by all these different vendors, products, regulations, concerns, and audits coming along,” she lamented.
“You cannot open up a newspaper or a news website without hearing about something to do with cyber or a hack or something like that.”
Ralph is right – the world is flooded with cyber-crime: even on the morning of Scot-Secure, news broke that Inc Ransom would release three terabytes of data it stole from the NHS Scotland health board.
The inescapable tsunami of cyber, it’s easy to feel burnout, overwhelmed, and ultimately alone.
“You’re not alone,” Ralph reassured. “No one actually fully knows what they’re doing in cyber. It is a cat and mouse game. It’s just figuring out how you map yourself to try and follow these trends, keep the fundamentals there, and then you should be able and be resilient against other things that come along.”
SonicWalls’ threat report revealed trends by of the continued invigoration of ransomware attacks, increased sophistication in malware, and newer exploits such as cryptojacking and threats to encrypted data.
Security concerns from executives and IT managers included cloud security, as more and more turn to cloud data storage capabilities, sometimes without enough knowledge of how this data is stored, transferred, and the data governance that comes along with it.
One of the most shocking statistics in the report, though, according to Ralph, is that 4% of cyber professionals who say they had not observed any incidents – including ransomware, phishing attempts, data breaches – in the past year.
“Burying your head in the sand won’t actually help,” Ralph said. “Perhaps they’re not seeing anything because they’ve got no tools or data to show them these types of events or threats,”
“If you’re not seeing anything, that’s not right either.”
So, admitting there is a problem is the first step, but then what can companies do to combat threat actors and keep their businesses and data secure?
Ralph suggests keeping it simple to start, beginning with the basics and fundamentals of security. Patch management, anti-malware, updating software, and anti-phishing training should all remain important.
But as threats transform and change, the basics shift and priorities need to be realigned.
“So, how do you secure yourselves with the world and the ever-changing threat landscape when you need to state your budget at the start of the fiscal year?” Ralph queried.
Cybersecurity’s prioritisation has doubled, according to SonicWall’s threat report. Ralph expects this statistic to continue growing.
“It will be exponential, especially as businesses are moving new operations into the cloud.”
But the cybersecurity world is varied, and budgets are constrained.
“How do you prioritise when it’s all just chaotic? And that is cybersecurity. It will always be chaotic,” Ralph said. “Anyone who says it won’t be is probably lying.
“We are living in a real environment. We are always catching up with the attackers, and we are behind them.”
What Should Your Cybersecurity Priorities Be?
To keep up with attacks, Ralph went into the top seven priorities for CISOs and CIOs, delving into what they mean, and what they may have forgotten.
Securing the cloud came in first: “We all love taking about the cloud and its a great thing to say, but if you’re using it, are you actually looking at security it, maintaining it, where it is hosted, or do you just sign a contract and forget about it and it becomes someone else’s problem?”
Ransomware came in next, and continues to baffle cybersecurity experts as scammers utilise new technologies to steal data. Ensuring that encrypted backups are made is a vital step in avoiding paying ransoms.
Ransomware had its third most prolific year on record, Ralph said, and sticking to the fundamentals is vital in preventing a costly reputational fallout.
Protecting user identities from attack and compromise was next on the list – this could be related to insider threats, but is also just related to all the data a company holds.
“Do you have a 24/7 threat model that’s looking at your intel pieces, or are you just looking at it Monday to Friday,” Ralph challenged.
Securing third party software and applications developed internally came further down the list, having Ralph question people’s budgetary scrutiny and consider the products they currently have for security.
Recommended reading
- UK’s First Cyber Incident Helpline to Support SMEs
- UK SMBs Face 37% Surge in Cybersecurity Warnings
- Scot-Secure 2024 | How to Effectively Threat Hunt
Rounding out the list were endpoint security and email security. While these may seem like less complex tasks, recent advancements and expansions in technology have made these even more of a priority.
Cryptojacking is a relatively new form of cyber-attack, where hackers gain access to any type of IoT device and use its energy for crypto-mining. This can be done on a laptop, a smart speaker like an Alexa, or even a smart washing machine.
“It’s not a spray and pay with cryptojacking. It’s much more involved, but it is still a low cost,” Ralph explained. “So its very very lucrative and it is preferred.”
2023 saw about a billion cryptojacking hits, and this is expected to grow exponentially as more and more IoT devices are introduced into homes and businesses without proper security.
The year also saw 240k intrusion attempts per second.
“That’s not a typo. That’s not a lie. That is what we see,” Ralph said.
So with all these advancing threats, how do companies begin to build resilience?
“It will never be fully managed,” Ralph conceded. Threat actors will continue to develop their assault tactics, without taking holidays or weekends, and they only have to be lucky once.
“So you have to remain resilient and become resilient. Look up the definition of resilient if you want to think how you should be securing your business and your customers and your staff’s data.
“It means you can weather the storm. So no, no one is fully protected, but at least with some level of resiliency, you are protected to certain types of attack and only the worst ones will get through or be successful.”
But with 51% of organisations only planning to increase cybersecurity investments when there has already been a breach, cybersecurity professionals are left a further step behind attackers.
“There is room for improvement, “The B word, budgeting, needs to be for resilience.”
Budgeting, and convincing a board to maintain or increase a solid cyber budget, is vital to ensuring a robust security posture. Presenting the economic and reputational consquences of a data breach or crypto-jacking attack may be necessary to educate the board on the real risks of a small budget.
Maintaining fundamentals, understanding your network concerns, delving into how vendors protect your assets, and proper data governance are all core to keeping up with the ever-evolving threat landscape.
But for Ralph, the main takeaway is simple: “Don’t be in that 4% who had their head buried in the sand thinking everything was fine.”





