Before the Gate – How to Survive in the Age of Cyber ​​Anxiety

AI Basics


The cybersecurity industry has been around for decades, but when it comes to digital business, I’ve never been more concerned about the safety of the digital space. Advanced finance, defense, healthcare, critical infrastructure, and areas of our personal lives rely on online nervous systems that are vulnerable to malicious forces. As more devices connect to complex networks, more vectors become available to cybercriminals.

The consequences of these attacks can range from costly to devastating. But what is crucial for boards is that they are becoming more frequent and more serious.

As if that wasn’t enough to attract attention, companies are also contending with an increasingly complex regulatory and litigation environment.

Preparing for a wide range of risks is essential, especially as regulators become increasingly aggressive and well-resourced and often seek to directly educate corporate officers and directors.

under siege

This means that there are three main trends that companies should address. A more controversial environment after a cyber incident. And there is a growing focus on personal responsibility.

Legislative perspectives are becoming increasingly complex in jurisdictions around the world. For example, in the UK, from the Computer Misuse Act 1990 and the EU Data Protection Directive 1995, through the Network and Information Systems Security Regulation 2018, to the UK General Data Protection Regulation 2021 and the upcoming EU AI Act. Along the way, businesses are grappling with myriad government interventions that affect their digital security. In the United States, the White House has released a National Cybersecurity Strategy aimed at improving cyber investment and risk allocation. The Australian government is also developing a national cybersecurity strategy and is foreshadowing significant legislative changes.

Additionally, cybersecurity is a multilateral issue, which creates a minefield with different regulatory regimes to contend with across the jurisdictions in which you operate.

Estimated global payments received by cyber-extortionists more than quadrupled annually from $174 million in 2019 to $765 million by 2020, according to Chainalysis . The raise has prompted some governments to consider intervening. Claire O’Neill has warned that the Australian government is considering a proposal to ban ransom payments. While the ban logically removes the commercial incentive for ransomware attacks, the proposal remains complex, especially when core assets and operations are affected by ransomware.

It is generally accepted that the broader costs of cybercrime will continue to rise even if the frequency and value of extortion starts to decline.

Relevant numbers tell their own stories. According to the United Nations Capital Development Fund, global cybercrime total direct losses in 2020 were approximately $945 billion. However, when you factor in indirect costs such as brand damage, intellectual property infringement, and lost opportunities, that number swells to about $4 trillion.

In this context, it is not surprising that regulatory oversight will become more stringent in the future.

Additionally, parties seeking to initiate class action claims are monitoring regulatory attention. Several class action lawsuits have been filed in Australia following recent high-profile data breaches, and affected organizations are also being investigated by the Australian Information Commissioner’s Office. Meanwhile, UK regulators are getting similar attention. The Information Commissioner’s Office has imposed two so-called ‘huge fines’ following recent data breaches, with Marriott fined £18.4m in 2020 following a cyber incident in 2014, British Airways was fined £20m after a data breach was discovered in 2018.

Of course, regulators who find a company’s cybersecurity inadequate may take a special interest in data breaches. This could be weaponized by plaintiffs, who could use the findings of regulators’ investigations to file lawsuits on behalf of affected companies.

This alone should be enough to get the board’s attention, but there is another weak point. It means that the personal responsibility of directors is once again in focus. While this is happening primarily in the United States, advisers warn it could be a harbinger of what’s to come globally. Companies operating in the UK financial services sector are already eligible for senior managers and certification schemes.

According to software company Lookout, 2022 will see a record high number of mobile phishing attacks. According to UK government statistics, 83% of companies reporting cyberattacks in 2022 identified phishing attempts as the attack vector.

Worryingly, advances in artificial intelligence (AI) are making these techniques more effective. A notable example is ChatGPT, OpenAI’s chatbot, which was recently exploited by cybercriminals to generate phishing emails, malware, and other malicious content. Of course, the potential for AI goes both ways and the technology can be deployed not only in cybercrime but also in cyber defense, but concerns are growing.

duck and cover

Insurance markets are usually good at putting a price on risk, and indeed some extraordinary policies have been taken out over the years. However, recent developments in the insurance industry are undermining confidence in the insurance industry to intervene to cover cyber risks. Last year, London’s Lloyd’s announced that its cyber policy would exempt it from attacks by state-sponsored attackers. At first this may not seem surprising. Warfare has long been excluded from insurance policies. However, this entitlement is disturbing as the question of whether threat actors have state backing is becoming increasingly unclear.

Moreover, legal clashes over whether the attacks were state-sponsored appear inevitable. For example, in 2022, pharmaceutical group Merck accepted a U.S. court’s argument that the war exclusion should not apply to the valuation of the $1.4 billion lost in the 2017 malware attack known as NotPetya. The distinction between digital warfare and digital crime has never been more blurred, and insurers want clarity in a still relatively young market.

Companies now face intense pressure to prove to insurers that they have a robust and workable strategy to defend against cyber incidents. Cyber ​​insurance is typically only available to businesses that can demonstrate an acceptable level of resilience. In addition, risks are driving up premiums, as are the severe losses suffered by cyber insurers in the early stages of the policy lifecycle.

eternal war game

It has been a popular phrase among military tacticians since 1880, when Prussian commander Helmut von Moltke said, “There is no plan to survive the first contact with the enemy.” But while this adage applies to issues of digital conflict and crime as well, the fact is that once cyber hostilities begin, a rigorously tested and flexible plan of action is far better than improvising. No change. Develop a consistent plan, broadly communicate it across the enterprise, use that plan strategically to maintain familiarity, socialize the types of questions the enterprise must answer, and uncover unforeseen problems. is the most effective measure a company can take to protect itself.

Cyber ​​security is not just about technology, it’s also about the human element. The absolutely basic thing is to train your employees and not lose sight of the human side along with the technical side. Even with all possible security vulnerabilities patched, a large-scale incident could still occur because someone’s credentials were stolen.

However, full board buy-in is required to ensure that the technical and human pillars of cyber resilience are adequately resourced and trained. Boardrooms need to recognize that things are going to change in the next few years, and that they are better off planning and budgeting for it and leading the way. Simply put, if every board member in every board in the UK had a switch on, directing proper preparedness and reviewing all this, the country as a whole would be much more resilient. .

The ultimate reality is that after two decades of being a mainstream concern, cybercrime is an increasing risk factor for businesses. The best defense is still not about cutting-edge technology, but about the humble business of sound organizational processes. Get the basics right: educate staff, keep software updated, back up data, and maintain sensible and actionable response policies. Risk and technology continue to change in the cyber space, but the basics of a well-executed but not flashy risk policy remain as relevant as ever.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *