News: 1674566405

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

The world is 'clearly' not prepared for cyberwarfare

(2023/01/24)


One-third of IT and security professionals globally say they are either indifferent or unconcerned about the impact of cyberwarfare on their organizations as a whole, according to a survey of more than 6,000 across 14 countries.

Security firm Armis commissioned the study, [1]published today, in an effort to gage cyberwarfare preparedness while the first [2]hybrid war wages on for nearly a year in Ukraine and [3]nation-state cyberspies make headlines almost daily.

The survey asked 6,021 respondents if they were confident that their organization — and government — could defend against cyberwarfare.

[4]

"The answer is clearly no," the [5]report says.

[6]

[7]

In an interview with The Register , Armis VP Chris Dobrec, said the finding that 33 percent of respondents aren't too concerned about cyberwarfare surprised him.

"Given the emphasis on cybersecurity over the last decade, where it's gone from stealing data to industrial espionage to out and out extortion with ransomware," he said. "And clearly the situation in Ukraine has heightened awareness. The geopolitical situation, from my perspective, has on the one hand, heightened awareness. But I was surprised that a third of respondents still don't feel prepared."

[8]

The incongruence rings true. Cybersecurity and organizations' [9]cyber preparedness took center stage in Davos at last week's World Economic Forum. During the annual meeting, the WEF released its 2023 Global Cybersecurity Outlook

[10]PDF

, which found that 91 percent of respondents believe a catastrophic cyberattack is at least somewhat likely in the next two years.

However, the respondents also cite a number of challenges, including trouble retaining trained staff in a competitive market and constantly evolving technologies and regulations, that leave them ill equipped to respond.

Similarly, a US General Accountability Office report

[11]PDF

published last week found federal IT systems and critical infrastructure face serious cyber risks that could harm human safety, national security, the environment, and the economy.

[12]

"We've made 335 public recommendations in this area since 2010," the GAO said. "Nearly 60 percent of those recommendations had not been implemented as of December 2022."

Almost half of orgs experienced 'act of cyberwar'

The Armis report echoes similar concerns. About 64 percent of those surveyed agree the war in Ukraine has heightened the threat of cyberwarfare. Additionally, 54 percent who said they are the sole IT and security decision maker for their organization said they've seen more threat activity on their network between May and October 2022 compared to the six months prior.

Additionally, 45 percent said they have had to report an act of cyberwarfare to the authorities.

But while almost a quarter (24 percent) of global organizations say they feel unprepared to handle the cyberwarfare threat, the lowest-ranked "security element" is preventing a nation-state attack, with only 22 percent selecting that as their top priority.

To be fair: several of the IT and security professionals' top priorities could fit under the heading of things to protect from nation-state attackers or indicators of a nation-state attack. Data protection topped the list with 60 percent choosing it as the No 1 priority.

The others are: intrusion detection (43 percent), vulnerability management (39 percent), threat visibility (38 percent), incident response (35 percent), risk assessment of IoT and OT connected devices (34 percent), preventing supply chain attacks (29 percent), machinery monitoring (24 percent), and, finally, preventing a nation-state attack – coming in at Number 10.

"I guess there hasn't been a strong enough correlation in security folks' minds that a lot of the criminal organizations behind the ransomware attacks of late are largely nation-state sponsored," Dobrec said. "So I'm hoping that this type of data brought out to the marketplace is going to increase awareness that you need to think about not only the cyber actors with economics in mind, but nation states behind them, as well."

[13]What keeps this FBI director up at night? China's AI work, for one

[14]Iranian cyberspies exploited Log4j to break into a US govt network

[15]Sandworm gang launches Monster ransomware attacks on Ukraine

[16]US offshore oil and gas installation at 'increasing' risk of cyberattack

Looking ahead, Dobrec said critical infrastructure operators and owners, followed by the transportation and logistics industries "should be on the highest alert" for nation-state or cyberwarfare attacks because these "could have devastating consequences from a human life perspective."

As the [17]cyberwar element of the war on Ukraine has shown the rest of the world, the threat landscape is bigger than it used to be.

"We used to spend all our energy on just the IT side of the house," Dobrec said. "But now we're seeing [cyberattacks against] OT systems, health-care systems, IoT, industrial control systems. The biggest thing that this is helping us to do is widen our aperture." ®

Get our [18]Tech Resources



[1] https://www.armis.com/cyberwarfare/

[2] https://www.theregister.com/2022/11/29/russia_ransomboggs_ransomware_ukraine/

[3] https://www.theregister.com/2022/11/16/iranian_cyberspies_log4j/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/governmenttechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9AOrr0sVgj0XociU4zCSQAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.armis.com/cyberwarfare/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/governmenttechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9AOrr0sVgj0XociU4zCSQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/governmenttechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9AOrr0sVgj0XociU4zCSQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/governmenttechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9AOrr0sVgj0XociU4zCSQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2023/01/22/fbi_director_wef_tech_panel/

[10] https://www3.weforum.org/docs/WEF_Global_Security_Outlook_Report_2023.pdf

[11] https://www.gao.gov/assets/gao-23-106415.pdf

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/governmenttechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9AOrr0sVgj0XociU4zCSQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2023/01/22/fbi_director_wef_tech_panel/

[14] https://www.theregister.com/2022/11/16/iranian_cyberspies_log4j/

[15] https://www.theregister.com/2022/11/29/russia_ransomboggs_ransomware_ukraine/

[16] https://www.theregister.com/2022/11/21/us_oil_gas_cyber_threats/

[17] https://www.theregister.com/2023/01/24/ukraine_nato_cyber_defense/

[18] https://whitepapers.theregister.com/



Pete B

That one-third who are indifferent are probably the ones who've been banging their heads against the beancounters for years for spend on security, and have now given up.

"The world is 'clearly' not prepared for cyberwarfare"

Mike 137

Spend is by far not the whole answer though. Most cyber attacks succeed mainly as a result of management deficiencies -- process failure rather than technology failure is commonly the primary trigger. One of the biggest contributors to this is the general incapacity to assess risks reliably. As a result the organisation's priorities don't accord with the threat landscape so they concentrate on fixing the wrong problems.

Re: "The world is 'clearly' not prepared for cyberwarfare"

ThatOne

That's true. Spend as much as you want, it won't prevent Joe from accounts opening that interesting-sounding attachment on that unsolicited email he just received...

(Of course you can ban all attachments, or have an air-gaped machine print emails out, but users tend to not accept things which make their lives even more miserable: They will quickly find means to bypass your barriers, potentially opening even bigger security holes in your perimeter security.)

Re: "The world is 'clearly' not prepared for cyberwarfare"

Anonymous Coward

I'm a relatively safe, snivelling miserable coward, because I delete every email that includes a link like "update your expired password" or includes an Urgent_Purchase_Order.pdf.exe "document". It's pretty much like wearing a mask in the office all the time which kept me happy during the COVID "warfare" years too - and now I'm happy to be a coward these days.

... "I have a total irreverence for anything connected with internet except that which makes the emails safer, the Windows updates stronger, the phone apps cheaper and the old men and old women receiving less malware in the winter and happier in the summer." (Brendan Behan would probably have said that these days).

elsergiovolador

Spend is by far not the whole answer though.

You still need people to even do spot checks in the office. For instance - has someone left the desk without locking their computer? Are there any access passes lying around? Any documents not secured?

Also to do things like leaving "infected" pendrives or memory cards, so when the worker decides to plug it in, it sends an email to security so you know which employee did this if it was inserted to company computer etc.

Sending fishing emails to see which employees follow procedures.

You also need people trying to breach the perimeter and see if any staff is challenging them for not having a pass etc. (and you need good actors for that)

Some of these tasks need to be done daily. If you stop, the staff gets relaxed after a while and falls into false sense of security.

ThatOne

> so you know which employee did this if it was inserted to company computer

You'd only know who found it, unless of course you empty a whole wheelbarrow of "lost" pendrives in the parking lot... Chances are 99% of those who pick one up will "just have a look", and if they suspect it could be virus-infected they'd rather try it on a company computer first...

.

> Sending fishing emails

Here again what might work for Jim might not work for Joe. You'd have to find some bait interesting/convincing enough to interest all employees, in which case I'm afraid a majority will fall for it. Often phishing emails just don't work because the target can't be bothered to react to them, inertia being a huge part of corporate security ("not my job, let someone else deal with that")...

Gene Cash

Well, if they find it and stick it in a company PC "for a look" they still need a beating. They're still willfully exposing the company to serious risk.

And if the "majority fall for it" then maybe the majority needs their email attachments privileges suspended for a month.

Edit: is it really too much to ask for people to have just a little bit of healthy suspicion? There's not much difference from getting a virus from purchase_order.exe than someone doing a $50,000 action on an email that's not actually from the CEO. Maybe they should double check first?

My backup server is offline

Grunchy

I only turn it on to do a backup, then I turn it off again. I dunno how the cyber-warfare ransomware expert is gonna attack it remotely when it’s off!

(I guess you could burn the house down to destroy it? You’d have to figure out where my street address is, and you STILL don’t know if I’ve got any worthwhile data at all [nope.] Or offsite servers [nope. MAYBE!])

F-35s

Black Label1

The moment one with a few electronics / radio gears and exploits is able to remotely activate the missiles of a F-35 - or crash it, will be really beautiful in cyber warfare.

If you permit yourself to read meanings into (rather than drawing meanings out
of) the evidence, you can draw any conclusion you like.
-- Michael Keith, "The Bar-Code Beast", The Skeptical Enquirer Vol 12
No 4 p 416