Cyber-attacks Cost Small US Businesses $25k Annually

Cyber-attacks Cost Small US Businesses $25k Annually

Cyber-attacks are leaving small businesses in the United States with big dents in their annual budgets, according to new research by international insurance company Hiscox.

Data analyzed in the creation of the “Hiscox Cyber Readiness Report 2021″ revealed that the average financial cost of a cyber-attack to a small business in the US over 12 months is “high at $25,612.”

The annual report, which was first published five years ago, surveys over 6,000 professionals from the US, UK, Belgium, France, Germany, the Netherlands, Spain, and Ireland who are responsible for their company’s cybersecurity. 

Respondents completed the online survey between November 5, 2020, and January 8, 2021.

Responses revealed that 23% of small businesses in the United States had suffered at least one cyber-attack during the past 12 months.

More than a third of US small businesses (35%) said that they do not fully disclose to all relevant internal and external stakeholders when a cybersecurity incident happens.

Other key findings of the report were that for small businesses, the most critical priority over the next 12 months is complying with the security requirements of their business partners (20%), over their own existing threats and vulnerabilities (18%). 

Many US small businesses (39%) said that they expect their security spending to increase over the next 12 months. Fewer than half (49%) reported having a cyber-insurance policy. 

Researchers found that the pandemic had created what they described as “cyber-stress” for small businesses in America.

With 63% of the small business workforce now toiling remotely, more than half (53%) of US small businesses perceive themselves to be more vulnerable to cyber-attacks.

“Small business can mean big business for cyber-criminals,” said Meghan Hannes, cyber-product head for Hiscox USA.

“We know the financial impacts of cyber-attacks can be substantial, and small businesses are increasingly feeling ‘cyber stress.’ The good news is, there are measures businesses can take to help mitigate the risk.”

Hiscox advises businesses to have a formal budgeting process in place and ensure cybersecurity is considered and prioritized in decision-making as a preventative step against cyber-attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Consumers Unforgiving of Merchants’ Data Failings

Consumers Unforgiving of Merchants’ Data Failings

New research has revealed that most American consumers who shop online will cease doing business with a merchant that mishandles their data.

The finding emerged from the May 2021 Securing eCommerce study, carried out by PYMNTS.com in collaboration with NuData, which surveyed a census-balanced panel of nearly 2,400 American consumers.

Shoppers were quizzed about their online buying habits and asked to share how they felt about a variety of related subjects, including data security. 

Nearly two-thirds of respondents (64.9%) said that they “are likely to terminate their relationships with merchants after experiencing even a single instance of data theft or payment fraud.”

Seniors and baby boomers were particularly unforgiving when it came to data security, with 80.2% stating that they would drop a merchant who failed to safeguard their data.

Generation Z were the most laid-back group of online shoppers in their response to data theft and fraud, but researchers noted that more than half of them (52.8%) would still ditch a merchant over a data breach.

Researchers found that the shift toward online shopping caused by the COVID-19 pandemic had led to increased anxiety over data security.

“Consumers are growing more anxious about their personal data being stolen, and their unease grows more acute as they spend more time shopping online,” states the report. 

“Forty-eight percent of all consumers say they are more concerned about data security than they were before the pandemic began, but this figure is as high as 57 percent among consumers who are buying more online than they were before the pandemic.”  

According to the study, online consumers are wont to pin the blame for data security gaffes squarely on the shoulders of merchants. 

A PYMNTS spokesperson said: “The Securing eCommerce study contains example after example of the new consumer mindset regarding who’s minding their data—or at least who they blame if something happens to that data. 

“The onus is clearly on merchants, more than banks or even card networks, to get it right.”

The study found that shoppers want merchants to provide money-back guarantees and share the steps they are taking to protect consumers’ personal data from fraud or theft.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Record Number of Breaches Detected Amid #COVID19

Record Number of Breaches Detected Amid #COVID19

A record number of breaches were analyzed in the Verizon 2021 Data Breach Investigations Report, with cybercrime thriving during the COVID-19 pandemic.

The study looked at a total of 29,207 security incidents from 83 contributors across the globe, of which 5,258 were confirmed breaches. This represented a substantial rise compared to last year’s report, in which there were 3,950 breaches identified.

There was a significant increase across a number of different attack vectors, which the researchers believe was fueled by the shift to home working as a result of COVID-19. Phishing and ransomware attacks went up by 11% and 6%, respectively, while instances of misrepresentation increased 15-fold compared to the previous year.

Well over half (61%) of the breaches analyzed involved credential data, and, in total, 85% of breaches involved a human element, according to the report.

Additionally, it was found that the rapid shift to the cloud during the crisis was heavily exploited by cyber-criminals, with attacks on web applications making up 39% of all breaches.

The report also noted significant variation in the way different industries were affected by cyber-attacks. For example, 83% of data compromised in breaches in the financial and insurance industries was personal information, while for professional, scientific, and technical services under half (49%) was of a personal nature.

Tami Erwin, CEO of Verizon Business, outlined: “The COVID-19 pandemic has had a profound impact on many of the security challenges organizations are currently facing. As the number of companies switching business-critical functions to the cloud increases, the potential threat to their operations may become more pronounced, as malicious actors look to exploit human vulnerabilities and leverage an increased dependency on digital infrastructures.”

Commenting on the findings, Eoin Keary, CEO and founder, Edgescan, said: “While it’s hard to establish causality, the data in the report confirms the impression that attackers certainly aren’t hindered in their efforts by global crises and are ready to opportunistically exploit any gap in the fence to pursue their objectives. For this reason, it is ever more important for the cybersecurity industry to come together and join forces to fight the challenges facing organizations today.”

Dan Conrad, IAM strategist, One Identity, said the report emphasized the growing importance of protecting credentials to secure organizations: “85% of breaches involved a human element—again, Identity is the security perimeter. We MUST find ways to protect us from ourselves,” he stated. “With that, I believe there is a shift in the mindset of the employee and consumer where they are starting to appreciate the protection of their own credentials. If we can protect our enterprises from our employees by simply embracing enhanced authentication (a.k.a. multifactor) then we are taking the right steps to protect our enterprises and adjusting the mindset of the user. In the new world of remote workers accessing everything from everywhere, anytime, ensuring they are who they say they are is critical.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Biden Executive Order Mandates Zero Trust and Strong Encryption

Biden Executive Order Mandates Zero Trust and Strong Encryption

President Biden has issued a long-awaited executive order (EO) designed to improve supply chain security, incident detection and response and overall resilience to threats.

Although every President in recent years has issued an order to improve the nation’s cybersecurity, experts believe this one is more detailed and has a better chance of success than previous efforts. It also comes amidst unprecedented attacks on US government and critical infrastructure, in the form of the SolarWinds, Exchange Server and Colonial Pipeline attacks, to name just a few.

Among the key measures is a requirement for all federal government software suppliers to meet strict rules on cybersecurity or risk being blacklisted. Eventually, the plan is to create an “energy star” label so both government and public buyers can quickly and easily see whether software was developed securely.

Other measures include an “aircrash investigation-style” Cybersecurity Safety Review Board, which will make recommendations for improvements after any major incident, and a standardized playbook for government incident response.

The EO will also mandate a drive to secure cloud services and zero trust, including multi-factor authentication and data encryption at rest and in transit, by default.

There are also provisions for government-wide endpoint detection and response (EDR), improved information sharing within government and between public and private sectors, and event logging requirements for federal government departments to enhance investigation and remediation.

The executive order has been welcomed by security experts.

Brian Fox, CTO and founder of Sonatype, argued that it will require suppliers and software companies in general to be more accountable for what’s in their code.

“While it shouldn’t have taken government intervention for businesses to practice proper software hygiene, Biden is harnessing the purchasing power of the federal government to advance software security — and this is something all nations would benefit from emulating,” he added.

Andrew Rubin, CEO of Illumio, praised the focus on best practice zero trust models for securing distributed computing environments.

“The Biden administration has unfurled a sweeping Executive Order finally acknowledging the failings of an outdated federal cybersecurity model, and laying bare the first iteration of a new security design — founded in zero trust,” he argued.

“Cyber complacency isn’t just an American problem, or a federal problem, or a policy problem – it’s a global problem. That’s why I welcome this executive order with open arms. It’s a call to action to the world that we need to change the way we protect ourselves. And with this new executive order — this new zero trust blueprint — we’re on the path to a more secure future.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Colonial Pipeline Attackers Linked to Infamous REvil Group

Colonial Pipeline Attackers Linked to Infamous REvil Group

The DarkSide ransomware group blamed by the US government for a crippling attack on a major East Coast fuel pipeline has been linked to a notorious variant used in extortion attacks against Apple and Donald Trump.

The DarkSide variant first appeared in around August 2020, but after a few months of operating it themselves, its Russian-speaking owners opened it up to affiliates, as most ransomware groups do today.

Researchers at Flashpoint claimed with “moderate confidence” that the owners of DarkSide are likely to have been former affiliates of REvil — a group in the news recently for its attempted extortion of Apple and supplier Quanta Computer and one of the most successful Ransomware as a Service (RaaS) operations around.

They also argued that the malware itself is based on the REvil code.

“The design of the ransom note, wallpaper, file encryption extension and details, and inner workings bear similarities to REvil ransomware, which is of Russian origin and has an extensive affiliate program,” Flashpoint claimed. “This shows the evolution path of this ransomware and ties it to other Russian-origin ransomware families.”

An analysis by FireEye pointed to an overlap between the two RaaS operations, but only in that some threat groups have probably been affiliates of both.

The Colonial Pipeline itself is reported to have resumed operations on Wednesday after five days out of action, although its website is inaccessible and the firm has claimed that service interruptions are still likely over the next few days.

The outage forced some states to declare an emergency as US motorists queued up to fill their cars and gas prices soared.

Investigators are still looking into the origins of the attack, although cyber-insurance provider Coalition, which last year bought cybersecurity firm BinaryEdge, reckons it may have found a “smoking gun.”

The firm claimed that Colonial was running a vulnerable version of Microsoft Exchange Server at the time it was hit, although remote scanning revealed it was also running exposed SNMP, NTP and DNS services.

“Other possibilities include the numerous network protocols exposed on the internet publicly, as well as targeted virtualization software or SSL VPN access with names that imply ICS network access – also with an invalid certificate,” argued Coalition’s head of threat intelligence, Jeremy Turner.

“Overall, Colonial Pipeline likely did not have the awareness needed to protect themselves. It could be as simple as a lack of two-factor authentication on their VPN — one of the most common threats to an organization’s cybersecurity — or it could have been an indirect victim of the general, and widespread targeting of Exchange servers.”

The US Cybersecurity and Infrastructure Security Agency (CISA) has released best practice guidance for organizations on how to protect themselves from ransomware attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Four Years On: Two-thirds of Global Firms Still Exposed to WannaCry

Four Years On: Two-thirds of Global Firms Still Exposed to WannaCry

Over two-thirds (67%) of organizations are still running an insecure Windows protocol largely responsible for the infamous WannaCry and NotPetya attacks of 2017 and 2018, according to new research.

Security vendor ExtraHop used its network detection and response (NDR) capabilities to analyze anonymized metadata from an unspecified number of customer networks, in order to better understand where they may be vulnerable to outdated protocols.

The resulting security advisory report revealed widespread use of Server Message Block version one (SMBv1), which contained a buffer overflow vulnerability which was exploited by the NSA-developed EternalBlue and related attack tools.

These were subsequently used by North Korean threat actors for WannaCry and Russian state operatives for their NotPetya operation.

This wasn’t the only insecure protocol ExtraHop found. It discovered that 81% of enterprises still use HTTP plaintext credentials, and a third (34%) have at least 10 clients running NTLMv1, which could enable attackers to launch machine-in-the-middle (MITM) attacks or take complete control of a domain.

The report also warned that 70% of enterprises are also running LLMNR, which can be exploited to access users’ credential hashes. These in turn could be cracked to expose log-in information, ExtraHop claimed.

Ted Driggs, head of product at ExtraHop, argued that it’s not always easy for organizations to upgrade to newer, more secure protocols.

“Migrating off SMBv1 and other deprecated protocols may not be an option for legacy systems, and even when it is an option, the migration can trigger disruptive outages. Many IT and security organizations will choose to try and contain the deprecated protocol instead of risking an outage,” he explained.

“Organizations need an accurate and up-to-date inventory of their assets’ behavior to assess risk posture as it relates to insecure protocols. Only then can they decide how to remediate the issue or limit the reach of vulnerable systems on the network.”

Wednesday represented the fourth anniversary of the WannaCry attack that impacted hundreds of thousands of users in 150 countries.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk