In 2024, the race between security specialists and cybercriminals will intensify further. The unstable geopolitical situation is contributing to an increase in the number of attacks. In principle, any business or public body with regional or national responsibilities could be affected. The problem lies in the discrepancy between the high level of professionalism among the attackers and the low level of resilience of many companies and public authorities. This is because behind many attacks lie highly professional groups – including states or government-affiliated institutions – which are always at the cutting edge of technology.
The use of artificial intelligence (AI) will take the quality of attacks to a new level: in future, phishing attacks will become even more sophisticated through the use of AI. Texts generated by AI are virtually error-free and deceptively authentic, making it increasingly difficult to distinguish between phishing emails and genuine emails. Furthermore, AI tools are increasingly capable of providing code or software, meaning that even hacker groups without their own software can make use of it, or they can access ready-made attack frameworks available on the dark web.
Firstly, this makes it easier to launch attacks; secondly, it broadens the ranks of cybercriminals to include people with little programming knowledge. Furthermore, AI systems can quickly adapt and improve known attack methods, or even provide answers on how to overcome obstacles. As a result, there will be more cybercriminals carrying out numerous and effective cyberattacks using professional and increasingly sophisticated methods.
The right response to every attack
On the other hand, IT infrastructures in many sectors are necessarily designed to facilitate the exchange of information and data in multiple directions – think of the cloud, Software-as-a-Service, working from home and connections to suppliers. In this context, a close examination of supply chains will become increasingly important. Vulnerabilities in the supply chain pose significant risks of attack. As there are many interdependencies within a chain, a single attack can cause damage in several places simultaneously and leave the processed data vulnerable. Public authorities and businesses should therefore make it a priority to consider their supply chains when addressing cyber security. The NIS2 Directive (see also here: NIS2 – Greater cyber security for the EU) obliges affected organisations to implement comprehensive risk management measures – including measures to secure the supply chain and address security-related aspects of the relationships between individual organisations.
Security is a cross-cutting issue in many areas of IT. The scope of what needs to be protected is growing ever larger, and, in the face of rapidly escalating threats, the necessary protective measures are becoming almost impossible for companies and public authorities to manage on their own. To stay one step ahead in this race, the cyber security industry must provide comprehensive security concepts as well as sophisticated, behaviour-based security measures. Here, too, AI and machine learning are becoming key factors in distinguishing normal user and system behaviour from anomalies and in countering sophisticated threats. Proactive and intelligent systems are crucial for identifying and neutralising threats.
As no one is immune to an attack, a coordinated approach between security and IT Services Continuity Management (ITSCM) or Business Continuity Management (BCM) will be necessary, ensuring that appropriate measures are taken in an emergency to minimise the impact on the company’s ongoing operations and business activities. This integration is vital to ensure a rapid return to full operational capability following a cyber attack. In future, it will no longer be simply a matter of isolating the organisation or public authority and ensuring under no circumstances that an attack is successful, but also of preparing for such an event so as to resume full operational capability as quickly as possible and with minimal damage.
External support
Given the wide variety of attack strategies, there are many defence strategies and individual solutions for securing specific areas. Furthermore, organisations must comply with regulations such as NIS2, DORA or the Cyber Resilience Act. The issue of cyber security is therefore becoming too complex for many companies and public authorities to tackle on their own. In order to build resilience, develop a comprehensive security strategy that takes the relevant requirements into account, select the appropriate security tools and establish the necessary processes within the organisation, organisations will increasingly turn to external consultants or procure security services, such as a Security Operations Centre (SOC).
With the launch of its Materna Radar Cyber Security brand, Materna has established a dedicated division in which all security services are bundled and delivered from a single source. The offering encompasses both cyber security consultancy and the integration of bespoke security solutions, as well as SOC services, which are operated in the cloud, on-premises or in a hybrid environment, depending on client requirements. The portfolio is being continuously developed to ensure that, as structures become increasingly complex, the company can continue to offer end-to-end solutions for complete processes.
For businesses and public authorities, it will be essential to think ahead in the field of cyber security, continuously expand in-house expertise and keep pace with the latest developments. Only those who embed their organisation within an ecosystem with external support – and thereby continuously and proactively improve their cyber security products, experts and processes – will prevail in the race against attackers.