Where to focus your cybersecurity defences in 2021

ramsac 2021 cybersecurity blog

Cybersecurity is constantly evolving; cybercriminals develop new ways of attacking individuals and organisations, while cybersecurity experts create methods to counteract these to defend and protect organisations. Verizon have published their 2020 data breach report, which is a great resource containing plenty of really interesting statistics. ramsac’s Technical Director, Paul Mew, has analysed the report to highlight some key points to help organisations to ensure they are focusing on the right areas to improve their security as we move into 2021.

Email phishing is rife

The vast majority of breaches in 2020 involved e-mail phishing attacks. Cybercriminals with a financial motivation were using stolen credentials, intercepting e-mails, changing payment information and creating fraudulent invoices to scam money from individuals and organisations.

“Social actions arrived via email 96% of the time, while 3% arrived through a website. A little over 1% were associated with Phone or SMS”.

There were also a large number of brute force password attacks and ‘password sprays’. Brute force password attacks target a website or application’s login page and automatically cycle through common passwords until the correct one is found. Password spays are a different approach, where the same commonly used password is attempted on thousands of accounts so as not to trigger an automatic lockout on those accounts.

Malware in decline, patching still important

Interestingly Verizon found there has been a steady decline in breaches from malware, including ransomware, during 2021. This is probably due to improved malware and anti-ransomware solutions such as Sophos Intercept X, and it tallies with what our support desk has been seeing, with fewer ransomware and crypto-locker type incidents compared to a couple of years ago.

Verizon also identified an interesting point around vulnerabilities, these were only exploited in around 2.5% of all breaches they reviewed:

“While successful exploitation of vulnerabilities does still occur (particularly for low-hanging fruit), if your organization has a reasonable patch process in place, and you do not have a state-aligned adversary targeting you, then your time might be better spent attending to other threat varieties.“

They also reported…

“…we took two samples from vulnerability scan data: organizations with the Eternal Blue vulnerability present on their systems and those without.

The systems that were vulnerable to Eternal Blue were also vulnerable to everything from the last decade or two. Once again, no, each new vulnerability is not making you that much more vulnerable”

This means provided organisations are patching regularly, a new vulnerability doesn’t immediately make an organisation significantly more vulnerable. It’s the organisations who don’t patch at all that are the ones suffering from vulnerability exploits (both new, and ones from ten years ago like Eternal Blue).

AHI and flying cars!

“For better or worse, the promise of fully autonomous Artificial Hacking Intelligence (AHI) is still at least 15 years away, along with flying cars.”

Artificial intelligence (AI) and Machine Learning (ML) are being used increasingly in our everyday life, from Netflix recommending what to watch next, to automated invoice processing. Artificial Hacking Intelligence (AHI) is where cybercriminals could in theory use AI and ML to automate attacks and find weaknesses in systems. Verizon have found that fully autonomous AHI is still a long way off, but more positively machine learning is already being used to spot attacks and take action to protect systems.

Protecting your organisations in 2021

Our advice for organisations to protect against cybercrime in 2021 is:

  • Have a strong password policy and implement multifactor authentication (MFA) on all accounts, across all systems. MFA will prevent the vast majority of attacks involving stolen credentials and is relatively quick and cheap to implement.
  • Ensure you are patching systems on a regular basis.
  • Provide users with regular cybersecurity training, including phishing e-mail testing
  • Have robust anti-malware, ideally with anti-ransomware and ensure it is kept updated.
  • Use an email system like Mimecast or Microsoft Defender for Office 365 to block malware and phishing via e-mail.
  • Ensure backups and business continuity plans are in place should the worst happen; you need to know how quickly you can restore/recover.

Organisations can never be 100% safe, users will make mistakes and it’s difficult to defend against someone who’s specifically targeting your organisation, but by putting the above processes in place will stop the vast majority of cyber-attacks.

Related Posts

  • The importance of cybersecurity contingency planning for businesses

    The importance of cybersecurity contingency planning for businesses

    Cybersecurity

    Protect your data from cybercriminals and minimise downtime with an effective cybersecurity contingency plan. Read on. [...]

    Read article

  • How to Spot a Scam HMRC Letter 

    How to Spot a Scam HMRC Letter 

    Cybersecurity

    Learn how to spot fraudulent communications, like fake HMRC letters, and take steps to protect your personal information and finances from scammers. [...]

    Read article

  • What is Data Loss Prevention (DLP)?

    What is Data Loss Prevention (DLP)?

    CybersecurityTechnical Blog

    Explore how Data Loss Prevention (DLP) strategies and tools protect sensitive data, ensure regulatory compliance, and mitigate risks from insider threats, enabling organisations to stay secure and resilient in [...]

    Read article

  • AI-Driven Threat Detection and Response

    AI-Driven Threat Detection and Response

    AICybersecurityTechnical Blog

    This blog explores how AI-driven cybersecurity is transforming threat detection and response with real-time, adaptive defenses against evolving cyber threats. [...]

    Read article

  • Why you should invest in Cybersecurity Consultancy

    Why you should invest in Cybersecurity Consultancy

    Cybersecurity

    n an increasingly complex cyber threat landscape, investing in cybersecurity consultancy is essential to protect your business from potential risks and ensure long-term resilience. [...]

    Read article

  • Everything you need to know about the transition to ISO 27001:2022 

    Everything you need to know about the transition to ISO 27001:2022 

    Cybersecurity

    This blog explains the essential steps and timeline for transitioning from ISO 27001:2013 to ISO 27001:2022, ensuring your organisation maintains its certification before the October 2025 deadline. [...]

    Read article

Quiz yourself

Are you more cyber savvy than an 11 year old?

11-14 year olds get asked these questions in school. Could you get these right?