An overview of the trends for 2023
Trend 1: Upgrading email security
One of the greatest threats to businesses and public authorities remains the ever-changing threat landscape surrounding ransomware and emails containing dangerous malware – or even a combination of both. Newer types of ransomware no longer necessarily rely on data encryption, but rather on data exfiltration. The attackers then exert pressure by threatening to publish the data.
Email security therefore remains a key priority for businesses and public authorities. To cover the main ‘vulnerabilities’, a three-part, comprehensive package of measures is required:
- Technology (website reputation checks, sandboxing, malware protection, continuous monitoring, event analysis),
- Staff and knowledge transfer (awareness-raising measures and training
- Processes (regular, prompt remediation of vulnerabilities, contingency plans and drills).
Trend 2: Making the overall system more resilient
As a consequence, we must consistently make systems more cyber-resilient. Zero-trust networks must be considered just as much as the securing of remote access. The Zero Trust Network Access (ZTNA) concept provides an intelligent, easy-to-implement and reliable approach. This enables organisations to reduce the risk of so-called lateral movement of malware within the network, as users are connected directly to applications rather than to the network. Zero Trust access is increasingly becoming a standard in the networking sector, one that must also be adhered to in wireless WANs.
Furthermore, the use of Endpoint Detection and Response (EDR) is strongly recommended – and Operational Technology (OT) security in manufacturing and industry must not be overlooked. A holistic and consolidated approach to security is becoming increasingly important in the context of risk management.
In the wake of the war in Ukraine, for example, there has been an increase in the use of wiperware. A wiper is a destructive form of malware that targets files, backups or the operating system’s boot sectors and attempts to damage and destroy an adversary’s systems to such an extent that recovery is impossible. These attacks will spread to other countries.
To ensure business continuity, organisations must focus on restoring the entire system so that not only the data but the entire IT infrastructure is operational again. Rapidly restoring the virtual version of a compromised physical system, for example, can significantly improve resilience.
Trend 3: Hybrid human-machine defence
Automated tools identify vulnerabilities in the infrastructure under attack – experts then assess these in terms of their attack potential. If companies – regardless of size or sector – do not wish to fall victim to such a sophisticated attack, they must also rely on hybrid defences. Companies must either train teams in-house or supplement them with external Managed Detection and Response (MDR) services.
Trend 4: Establishing proactive defence
Cybercriminals are becoming increasingly professional and are taking an ever more targeted approach. Ransomware-as-a-Service on the dark web is making it more attractive to anyone wishing to sabotage competitors or exploit cyberattacks for political gain. IT managers must therefore not only effectively detect anomalous activity on the network and at endpoints, but also proactively counter the attackers. Features such as ransomware honeypots can specifically trigger and actively counter the attackers’ actions before the cybercriminal carries out their overall plan. Anyone wishing to defend against such threats should definitely seek the help of external cybersecurity experts or, looking ahead, consider setting up their own Security Operations Centre (SOC) with a tried-and-tested, operational Cyber Defence Centre solution.
Trend 5: Securing the software supply chain
There are an increasing number of attacks on the software supply chain; between 2020 and 2021 alone, they rose by 300 per cent. Securing software will therefore be at the top of CISOs’ priority list in 2023. Specifically, they must invest primarily in solutions for analysing software composition, securing the toolchain and in ‘Software Bills of Materials’ (SBOMs for short). As a result, demand for development security specialists (known as DevSecOps) will also rise sharply.
Organisations should ensure that their software suppliers implement security policies, use tools to secure their entire development process, and can guarantee the provenance and security of all software components via a complete SBOM.
This refers to SBOMs and, for example, DevSecOps, which take security aspects into account at an early stage in software development (software components, code, etc.) and review them on an ongoing basis.
Source: RADAR Cyber Security