Since the pandemic the cyber world has become a far riskier place. Even more alarming is that these attacks are happening despite businesses doubling down on their cyber security spend.
Cyber security is at a critical inflection point where five mega trends are making the threat landscape riskier, more complicated, and costlier to manage than previously reported. To better understand the evolution of this threat landscape, let’s examine these trends in more detail.
- Everything becomes digital
The sudden explosion in connectivity has accelerated digital transformation in governments and businesses by almost seven years, according to a McKinsey report. With infrastructure and related services far more internet accessible than they were pre-COVID, attackers have gained ample opportunities to compromise remote users, vulnerable systems, and defences.
The pandemic also forced workers to become more digitally dependent. The corporate perimeter that traditionally protected employees in an office setting has today become irrelevant. Workers are accessing corporate resources from personal devices, using unsecured public Wi-Fi networks, and putting organisations at increased risk of breaches and cyber attacks.
- Organisations become ecosystems
Organisations are opening their infrastructure and resources to an extended body of manufacturers, supply-chain suppliers, and partners to share information and make trade barriers less obtrusive.
Such changes are posing cyber risks for organisations because it is challenging to manage, secure, and regulate an entire ecosystem that is beyond the control of the enterprise. Cyber attacks in the supply chain jumped 51 per cent last year according to an NCC Group study.
- Physical and digital worlds collide
As physical and digital worlds overlap, a hybrid threat landscape will emerge where attacks in cyber space will have implications in the physical world (and vice-versa). This can come in the form of business disruptions, physical security and safety of infrastructure, theft or loss of confidential data, litigations, and even loss of life.
Gartner predicts cyber attackers will weaponise operational technology (financial systems, fuel or gas pipelines, power grids, water supply, healthcare or the internet itself) to harm human life.
- New technologies bring new risks
The emergence of technologies like internet of things, multi-cloud, 5G, and edge computing will create tens of billions of hackable devices and numerous entry points that attackers can exploit. Artificial intelligence will be subject to manipulation which can even institutionalise bias and make unfair or even unsafe judgments. The more connectivity the world has, the more widespread is the potential for disruption.
- Regulations become more complex
The massive surge in cyber attacks and breaches is creating an urgent need for governments to regulate activities in cyber space. Almost every major country is issuing some form of data protection or privacy legislation.
Regulations are evolving fast and depending on the number of geographies in which a business operates, tracking and implementing regulatory mandates can be a complex endeavour. Non-compliance can expose businesses to pitfalls including operational failures, costly fines and penalties and loss of customer trust.
Cyber security will always be a work in progress. The key to effective risk management is having proactive visibility and context across the entire attack surface. This helps to understand which vulnerabilities, if exploited, can cause the greatest harm to the business. Not all risks can be mitigated; some risks will have to be accepted and trade-offs will have to be negotiated.