07.02.2023
Blog
Cyber Security

Why the early detection of cyber attacks is crucial for businesses

According to the study’s findings, it takes an average of five months for a security incident to be detected – valuable time during which it would be possible to prevent or limit the damage. Find out what approaches are available to detect attacks earlier and avoid the resulting high costs.

Thorsten Kuhles
Cyber Security Incident Manager

The findings of studies on the detection of illegal activities by attackers within corporate networks are alarming. According to IBM Security’s 2021 Cost of a Data Breach study, it takes an average of 151 days for hackers to exploit access to a network undisturbed, in order to spy on the organisation’s infrastructure, obtain further passwords and ultimately carry out an attack.

The devastating consequences

A look at the Ponemon Institute’s Cost of Cybercrime Study reveals how long, on average, it takes organisations to fully recover from various cyberattacks. Recovery is quickest in the case of malware attacks, taking around 6.4 days, and for botnets, taking around 2.5 days. Ransomware attacks take an average of 23.1 days to resolve, whilst attacks involving malicious code take as long as 55.2 days. Extortion Trojans, in particular, are highly favoured by attackers, and trends such as Ransomware as a Service (RaaS) must be taken very seriously by companies.

With every day that an attack goes undetected, or that passes whilst the effects are being remedied, the costs for the affected company rise to an unforeseeable extent. According to Bitkom, the damage to the German economy amounted to approximately 225 billion euros for the years 2020/2021. Unfortunately, these soaring costs are also fuelled by the fact that companies are still investing too little in proactive measures, such as Cyber Threat Intelligence (CTI) or self-initiated vulnerability tests (penetration tests). The risks are constantly increasing, even for ‘inexperienced’ hackers, due to ever-improving attack techniques and the ease with which these can be exploited. The key challenge in defending against attacks is therefore the early detection of suspicious activity on the network.

Prevention rather than cure

There are several preventative approaches which, ideally, should be applied in combination within a company. A first step is to ensure that current attack techniques are known and understood. Only in this way can a company implement the proactive countermeasures appropriate for its own systems. It is also advisable to monitor and analyse activity within the organisation’s own network using appropriate tools, and then to initiate the next steps in collaboration with internal or external experts, such as those from a Cyber Security Incident Response Team (CSIRT). This requires early planning and the implementation of a company-wide incident response policy, which should comply with international standards such as ISO.

However, the involvement of all a company’s staff also makes a vital contribution to early detection. Awareness campaigns can raise awareness of the dangers of a cyber attack, and all staff are involved in the process of enhancing a company’s IT security. After all, if everyone is aware that they are the first line of defence against a cyber attack, potential attackers have less chance of succeeding, for example, via phishing emails.

Large organisations implement their own Security Operations Centres (SOCs), which are dedicated exclusively to monitoring network activity around the clock. For small and medium-sized enterprises, such a SOC represents a financial burden that is far too great. Nevertheless, there are viable options whereby an external service provider can take over the monitoring and analysis of internal information. The Materna SOC Service offers precisely these functions. Using its dedicated solution, the SOC monitors logs from operating systems, servers, databases, routers and other systems on the network. If the system detects suspicious activity, the SOC team immediately informs the Materna CSIRT, which then, depending on the agreement, initiates an immediate response in collaboration with the company. This service can, for example, minimise the risk of data encryption resulting from a successful ransomware attack.

Conclusion

There is therefore the potential to reduce the time taken to detect unauthorised activity within one’s own network from an average of over 150 days to seconds or minutes. The current situation shows that the key to success lies in proactive measures, such as vulnerability testing carried out without specific cause, or trend detection via CTI. However, increased investment in employee engagement also plays a crucial role in raising a company’s security level. The motto ‘The first line of defence is YOU’ should therefore not just be displayed on a poster on the wall somewhere, but should be put into practice at all levels of the organisation.

Thorsten Kuhles
Cyber Security Incident Manager

Thorsten Kuhles verantwortet als Cyber Security Incident Manager bei Materna die interne und externe Vorfallsbearbeitung. Zuvor war er langjährig u.a. im Bereich Pentesting und IT-Forensik bei der Bundeswehr sowie in Führungspositionen im Bereich Cyber Security bei namhaften Unternehmen tätig.