Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The Three Rs of Today’s Cybersecurity Landscape: Risk, Ransomware and Reputation

by The Gurus
January 30, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

One of the most valuable weapons in any cybersecurity specialist’s arsenal is insight. Accessing and analysing data about threat types, volumes, methods and motivations offers a critical edge when designing an effective security posture. At Carbon Black we consider our Threat Analysis Unit (TAU) to be a vital part of what we do to help customers counter the threats they face. The latest intelligence to come out of TAU shows us that 2017 was a year of ballooning risk, rampant ransomware and growing awareness of the reputational damage that security breaches inflict. Here’s what we learned…

 

The risk of attack grows ever higher

The number of attacks is increasing exponentially – by 328% in fact. At the start of 2017, the average computer protected by Carbon Black was targeted by an attack 0.7 times per month. By December 2017 that number had leapt to three attacks on average per computer, per month. As a trend there was a 13% monthly growth rate in attacks on endpoints in the course of 2017. This means that an organisation with 10,000 endpoints is seeing an average of 1000 attacks per day.

 

The type of attack is changing, too. We saw linear average monthly growth in the rate of non-malware attacks of 6.8%, these kinds of attacks comprising 52% of all attacks. Non-malware attacks use authorised software to gain a foothold in the target system and are therefore hard to detect using signature-based anti-virus software.

 

This increase in the volume and evolution in the type of attacks has provoked an increase in organisations’ expenditure on security. Gartner has predicted that spending on security will rise by 7% in 2018 as companies invest to safeguard themselves with next generation anti-virus software that is up to the challenge of detecting and stopping non-malware attacks in their tracks.

 

The year of ransomware

2017 might have been the Chinese Year of the Rooster but the only crowing that security experts heard came from the army of cybercriminals who made it the year of ransomware. The ease of anonymity offered by TOR, the rise of cryptocurrencies to facilitate payments and the emergence of ransomware-as-a-service all contributed to this bumper year. Technology, government and legal industries bore the brunt of what amounted to a $5bn crime spree, according to Cybersecurity Ventures Research, with that sum handed in ransoms to criminals. With a paycheque that big in front of them, and little hope that the world will remove the incentive by refusing to pay ransoms, they are unlikely to change tactic any time soon.

 

Accepting that sad fact, it’s up to businesses to protect themselves unilaterally from attacks that can damage their networks, profits and – since the catapulting of ransomware into the public awareness – their reputations.

 

Reputations rocked by ransomware

The Wannacry and NotPetya attacks drove ransomware into the public consciousness properly in 2017, with more than half of the population experiencing it for the first time. They were quick to form judgements about where responsibility for protecting against ransomware attacks lay: squarely with individual businesses. Our research showed that 70% of consumers would consider ceasing to trade with a retailer, healthcare provider or financial institution that was affected by ransomware.

 

Linked to this is the fourth “R” (forgive me for adding to the traditional triumvirate) that is starting to have an impact on security postures and that is “regulation.” The enacting of the GDPR in May will see one particular security challenge brought into the spotlight and that’s the time it takes to receive a breach notification. As we’re all aware, the new regulation requires organisations affected by a data breach to inform affected data subjects within 72 hours of its occurrence.

 

Research we carried out earlier this year showed that organisations were suffering from a lack of data visibility and were not confident that the toolsets that they have in place for classifying critical data and identifying and prioritising risk to that data were effective and easy to manage. This shortcoming means that security teams can struggle to identify the suspicious behaviour on the network that could indicate a fileless attack in progress. Without the ability to detect a breach, organisations will run the risk of failing to notify compromised data subjects within the required time scale. Plus, and perhaps more concerningly in the immediate term, they’ll also be under an attack that they don’t know about!

 

This current state of the nation can seem like a bleak picture with attacks increasing, ransoms growing and reputations under fire, but there are positives, too. The security industry is fighting the good fight, using every weapon in our arsenal to defend against attacks as they evolve. We’re developing ever more sophisticated defences that can detect and stop fileless attacks before they breach the perimeter, and using threat intelligence to understand the motives, drivers and methods of our adversaries. What we do is not just a matter of business, it is a matter of pride.   From more analysis from the unit or for more detail on the threat horizon, why not download our latest report: Carbon Black 2017 Threat Report.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Salaries for cyber security professionals set to rise in 2018

Next Post

Improve collaboration to overcome cyber-attack security issues, say transportation security leaders.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol