Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 27 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Understanding Modern Cybersecurity Anatomy.

by The Gurus
May 31, 2019
in Opinions & Analysis, Security News
Understanding Modern Cybersecurity Anatomy.
Share on FacebookShare on Twitter

By Dr Darren Williams, CEO and Founder Of Cyber-Security Firm, BlackFog

Antivirus software was born over 30 years ago when computers were still relatively new. At that time, antivirus software was king as it defended against one of the only existing threats – viruses. However, 30 years on much has changed – and in the world of technological advancements, three decades might as well be a lifetime.

The threat landscape we see today is vastly different and infinitely more sophisticated. Organisations must protect their devices not only from viruses and malware such as ransomware, but also malicious activities carried out by cybercriminals, including infecting Internet of Things (IoT) devices to perform DDoS attacks. That’s why the days of protecting yourself from bad actors using a single antivirus solution are now behind us. Fileless network protection is a key element to device security and an important part of the layered security strategy which is vital to protecting organisations today.

Signature Based Detection

Sophisticated (and not so sophisticated) attackers can today easily avoid detection from this signature-based software. As protection through an antivirus software is based upon prior knowledge of the attacker, naturally, cyber criminals are aware of this and attacks are now specifically designed to avoid this entire process. They now use fileless techniques to download random payloads and signatures to completely avoid detection. In fact, fileless based attacks are increasingly on the rise with 77% of successful attacks now using fileless exploits. And worryingly, fileless attacks are ten times more likely to succeed.

Traditional antivirus security products rely on signatures to detect and remove threats. This fingerprinting technology looks at every file on your device and generates a unique identification number, or signature. This signature is then compared to a database of known bad actors. When a match is found the offending file is removed.

These products scan an organisation’s filesystem and current processes looking for bad signatures. However, it is important to understand the limitations of this technique in terms of device and data protection.

Firstly, the bad actor needs to be identified. Just like in the real world, after a break-in the police have to arrive at the scene, investigate and take fingerprints and then compare them to a list of known criminals. This is no different in the digital world. It takes teams of people to identify, analyse and classify the problem.

Secondly, after it has been verified it can be added to a database and made available to clients. This takes time. Typically, the best-case scenario is around 4 hours however it is usually significantly longer taking up to 24 hours or more.

The problem is that the majority of cyber-attacks do the most damage within the first few hours, spreading across the globe rapidly. Recent examples include WannaCry and Petya. In fact, the WannaCry ransomware attack was, at the time, one of the most devastating and widespread cybersecurity incidents recorded. It took just four hours to spread across the NHS, ultimately affecting 34% of NHS trusts, as well as more than 600 primary care organisations in the UK. Total global losses resulting from the attack placed at anywhere between hundreds of millions to an eye-watering $4 billion. With devastating cost and reputational impact organisations simply can’t hesitate when it comes to stopping an attack in its tracks.

Behavioural Profiling

Rather than focus on identifying attackers by their fingerprints, organisations need to take a different approach and instead look at the characteristics of what makes an attacker different than a normal application. For example, analysing network traffic to detect unusual behaviour.

Typically, attackers use fileless techniques to avoid detection and either download or execute remote payloads with the purpose of stealing data. To do this it is necessary to connect to a remote server. Since this needs to remain anonymous to avoid detection, it is usually performed over the dark web. However, new solutions are available that can stop the attacker at each stage of the cycle.

Fileless malware will only become smarter and more common. Increasingly, attacks will leave little to no tracks in the file system and in the network and will force organisations to start detecting attacks based on their behaviour.

With government data released in 2017 showing that almost half of UK firms were hit by cyber breach or attack in 2016, the rise in major security incidents has certainly urged organisations to reassess their cybersecurity strategies in the past 12 months. However, companies still have a long way to go in bolstering their cybersecurity defences in the long term. The challenge for businesses is to drive cybersecurity change now and not wait for the next big attack before they bring their security processes up to date.

Share4Tweet
Previous Post

Radiflow iSID Industrial Cybersecurity App Now Available On Cortex By Palo Alto Networks.

Next Post

The majority of the UK’s top websites fail GDPR.

Recent News

Keeper Security launches Microsoft Teams integration for privileged access management

Keeper Security launches Microsoft Teams integration for privileged access management

June 26, 2026
UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

June 25, 2026
pqc

New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security

June 24, 2026
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

June 24, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol