Skip naar inhoud

IT leaders fear ‘trickle-down’ of nation-state cyber attacks

Wilt u deze bijdrage aanbevelen? Dat kan via:

Three-quarters of IT decision-makers are concerned that the tactics, techniques and procedures used by nation-state attackers could be used against them
Almost three-quarters of IT executives are concerned that the trickle-down of cyber attack tactics, techniques and procedures (TTPs) used by nation state-backed actors will impact their business, according to new data from HP Wolf Security, HP Inc’s endpoint protection unit.A total of 1,100 IT decision-makers were polled by Toluna in Australia, Canada, Germany, Japan, Mexico, the UK and the US earlier in 2021, and the pollsters found that 72% of them feared that nation-state TTPs could filter through the dark web and be used against them.

HP Wolf said this fear was justified, because evidence has already emerged that ransomware gangs unaffiliated with Russia’s APT29 or Cozy Bear, the group that hacked the SolarWinds Orion platform in a US-focused espionage campaign, have used some of the TTPs leveraged by the spooks in their own campaigns.

“Tools developed by nation states have made their way onto the black market many times,” said Ian Pratt, global head of security for personal systems at HP Inc. “An infamous example is the Eternal Blue exploit, which was used by the WannaCry hackers.

“Now the return on investment is strong enough to enable cyber criminal gangs to increase their level of sophistication so that they can start mimicking some of the techniques deployed by nation states, too.

“The recent software supply chain attack launched against Kaseya customers by a ransomware gang is a good example of this. This is the first time I can recall a ransomware gang using a software supply chain attack in this way.”

Pratt said the Kaseya incident had created a blueprint for financially motivated threat actors to monetise attacks developed by nation-state actors, which meant they were now likely to become more widespread.

“Previously, an independent software vendor [ISV] with a modest-sized customer base that didn’t supply government or large enterprise may have been unlikely to become targeted as a stepping-stone in a supply chain attack,” he said. “Now, ISVs of all types are very much in scope for attacks that will result in compromised software and services being used to attack their customers.”

Besides the risk from cyber criminals, more than half – 58% – of decision-makers said they were concerned about being directly targeted by a nation state, and 70% feared they could end up becoming collateral damage in a hypothetical future cyber war. The main concerns relating to nation-state attacks were sabotage of IT systems or data, disruption to everyday operations, data loss or theft, and revenues loss.

“This is a very real threat that organisations need to take seriously,” said Pratt. “Whether defending against a cyber criminal gang using nation-state tools and techniques, or a nation state itself, organisations are facing an even more determined adversary than ever before.”

He advised decision-makers to re-evaluate how they go about managing cyber risk. Given that no single tool or technique can possibly guarantee 100% protection, leaders must take a more architectural approach to cyber, said Pratt.

“This means mitigation through robust security architectures that proactively shrink the attack surface, through fine-grained segmentation, principles of least privilege, and mandatory access control.”

Lees ook:

Help een jongere zijn studie door, doneer nu je oude laptop.

Het zal u vast nog niet ontgaan zijn, maar door de hoge inflatie is alles duurder geworden. In sommige gevallen zelfs te duur, zoals een nieuwe laptop voor een studie.

Wat wil en wenst de ontwikkelaar?

In een krappe ict-arbeidsmarkt is het voor werkgevers interessant te weten wat er onder ontwikkelaars leeft. Bedrijven die de juiste tools bieden, hebben een streepje voor. Een internationaal onderzoek onder ruim zeventigduizend ontwikkelaars uit de Stack Overflow-community geeft inzicht in de trends. Dit rapport is bij recruiters dan ook niet onopgemerkt gebleven. Ze krijgen zo een beeld van hoe developers leren en meer kennis vergaren, welke tools ze gebruiken en waaraan ze behoefte hebben.

TNO: Europa kan tech-overmacht VS en China doorbreken

Zet vol in op de ontwikkeling van 6G, maak Gaia-X volwassen, loop voorop met edge computing en omarm open technologie. Dit zijn enkele aanbevelingen van TNO om in Europa de overheersing van Big Tech en Chinese (5G-)bedrijven te doorbreken.

Subpostmaster campaigning forces government to set up compensation scheme and make interim payments

Subpostmaster campaign group is a step closer to achieving what it was originally set up to do as government launches compensation scheme for its members who did not receive fair payouts

Advies: wacht met 3,5 GHz tot Inmarsat weg is

Het duurt waarschijnlijk tot eind 2023 voordat de 3,5-GHz-frequentieband beschikbaar komt voor openbare mobiele-communicatiediensten. Er is weliswaar veel vraag naar extra frequentieruimte, maar op de daarvoor afgesproken 3,5-GHz-band kan dat storen met noodoproepen van de lucht- en zeevaart. Het ministerie krijgt het advies te wachten totdat satellietbedrijf Inmarsat is verhuisd van het Friese Burum naar Griekenland.

Na sase komt sse (security service edge)

Security service edge (sse) is de evolutie van het sase-framework van Gartner. Door de letter ‘A’ (voor ’access) te verwijderen, wordt duidelijk dat het netwerk niet langer wordt beschouwd als onderdeel van een beveiligingsoplossing. Het is slechts het mechanisme dat de datastromen naar het security- en controleplatform transporteert.

Wilt u deze bijdrage aanbevelen? Dat kan via:

Klaar voor de beste oplossing voor uw IT & ICT-situatie?

Ik heb mijn wachtwoord gewijzigd in “onjuist.” Dus wanneer ik vergeet wat het is, zal de computer zeggen: “Uw wachtwoord is onjuist.”