2020 brought huge changes to the cybersecurity risk landscape. The impacts of the COVID-19 pandemic are still ongoing and the opportunities for new cyberattacks across different sectors are more real than ever.
Knowing your posture toward cybersecurity best practices and then effectively remediating are two steps to strengthening security across organizations. Before you make your first assessment, however, it’s important to stay informed about where hackers and understand the risk that arises with changes in the current landscape. Focusing your efforts will help you inform your management for 2020 and beyond.

Cybersecurity risk in the supply chain
Supply chain attacks increased by 78% in 2019 according to Symantec, and this exponential growth is not expected to slow down in 2020. Supply chain cybersecurity is a constant area of concern for many businesses.
Organizations without dedicated suppliers or third-party risk teams often struggle to assess the security of their supply chain. The complexity created by increased digitalization, business growth, and third-party partnerships increases the need to protect sensitive information, including financial, personal, and strategic information such as intellectual property.
COVID-19 has caused travel restrictions that have limited the number of assessment organizations and service providers that can conduct on-site assessments, creating a gap in supply chain security program activities. Some businesses are approaching this issue by asking suppliers for reports on how they have changed their cyber risk management strategy to accommodate these changes. Where possible, supplier risk management teams are encouraged to track a supplier’s cyber risk posture not only through risk assessments, but also through security, policy and process audits through a single reporting system, such as an integrated risk management solution.
Especially for organizations that work with many small businesses, which are at the greatest risk for cyberattacks ,knowing where security gaps lie in the supply chain is crucial.
Cybersecurity risk of being human
In times of crisis and uncertainty, cybersecurity teams must remain vigilant and act proactively to ensure that employees across their enterprise are not caught in the crossfire. Awareness and education, as well as prioritizing employee mental health, should be a priority for companies.
Cybercriminals try to exploit your weaknesses – whether it’s not having 2FA enabled or you’re careless and clicking on a link in a seemingly innocent email. Both of these are examples of opportunities for cyber incidents that arise from human error. Implementing a virtual awareness and training program or conducting weekly security training that details the most common cyber attacks and how to spot them on a daily basis may be what organizations need to do to properly inform their employees.
Especially in sectors like hospitals and healthcare, prioritizing awareness and training is essential. DDoS attacks in the Health and Human Services sectors were just the beginning. It is also worth noting that while many of these cyberattacks are designed to occur quickly and cause rapid disruption, some of the more sophisticated state-sponsored hackers will exploit organizations that are busy maintaining day-to-day operations and transitioning to remote work by taking a longer-term approach to creating disruption.
Human error manifests itself in many ways, and the data shows that it’s not just awareness and education that can make a difference. The other area we need to focus on – mental health – may not be discussed as much, but in unprecedented times like the ones we’ve experienced in 2020, it’s more important than ever to support employees . Positive morale and the mental flexibility and alertness that come from a healthy psyche are largely the responsibility of managers and employers.
Building a healthy and balanced culture in times of uncertainty could help prevent opportunities for cybercriminals .
Cybersecurity risk in corporate governance
The interconnected risks fueled by the events of 2020 require greater oversight from information security and cybersecurity teams and the board. A clear area of cybersecurity risk in 2020 will come from the weakness of corporate governance functions that will not have the same level of effectiveness they had when they were done in person.
If board members become ill or unable to perform their duties, there must be a plan. Organizational leadership must be confident that business will be able to maintain operations regardless of cybersecurity incidents. Executive meetings should be organized in virtual or hybrid ways, while maintaining their ability to work as a team and react quickly and accurately in times of crisis, especially if a cybersecurity incident occurs.
Creating clear incident response plans and maintaining cybersecurity through a comprehensive risk management approach is recommended for leadership regardless of business scale.
