HomeSecurityCOVID-19: The new reality in cybersecurity

COVID-19: The new reality in cybersecurity

Most businesses do not have adequate security systems in place to support remote work and now have to deal with the new reality of COVID-19 that includes a wider range of attacks and less secure devices. Many businesses have also had to adapt and quickly adopt various digital tools, using new technologies that may not be sufficiently secure.

21% of organizations in Singapore revealed that they have seen an increase in attacks on their IT systems due to the pandemic, according to a HackerOne report released this week. About 58% of these businesses believed they were more likely to experience a data breach as a result of the global pandemic. The HackerOne study was conducted by Opinion Matters in July 2020 and published the results for 1,400 security professionals in Singapore, Australia, France, Germany, Canada, the United Kingdom and the United States.

64% of boards considered it likely that their organization would experience a data breach as a result of the pandemic. HackerOne CEO Marten Mickos said: “The COVID-19 crisis has moved everything online. As companies rush to meet remote work and customer demands for digital services, attacks have expanded dramatically, with security teams understaffed to deal with them.”

COVID-19

With most employees working from home, it has become easier to carry out attacks on businesses, warned Eugene Kaspersky, CEO of Kaspersky, who spoke at Kaspersky's Asia-Pacific Online Forum last week.

The security vendor reported a 25% increase in the number of new malicious apps to more than 400,000 per day, up from 300,000 before the virus emerged. Kaspersky said this is the new reality and the right strategy is even more important at this stage.

David Koh, commissioner and CEO of the Cyber ​​Security Agency of Singapore (CSA), agreed, noting that governments, industries and individuals had to change the way they live and work, and all in a very short period of time.

Companies had to adapt to working from home and bring partners and customers online, Koh said. “Things that some people thought were very difficult to do nine months ago had to change overnight,” he said. “We had to radically adapt and use new technologies literally overnight.”.

Databases, for example, had to be expanded so that employees could access them from their home environment, and the controls that previously existed in physical workplaces were no longer relevant.

Instead, employees' home Wi-Fi systems were now the main connection hubs, and these were not as secure as the office environment, Koh said.

Employees had been moved out of offices and into homes, but organizations had not installed security systems outside their business walls, said Mark Johnston, Google Cloud's Asia-Pacific security lead for networking and collaboration specialists.

Cybercriminals have also adapted, broadening their focus to leverage public interest in COVID-19 as a lure for scams and ransomware.

New vulnerabilities were also exposed because users had moved outside their corporate environment and were no longer protected by firewalls, Johnston said.

There was also an increased focus on credentials, as more people accessed the corporate network from different home and online environments, he noted.

Mihoko Matsubara, chief cybersecurity strategist, said: “We are now more vulnerable because so many companies have embraced remote working.” She noted that 45% of organizations in Asia had not yet provided training to guide employees on how to work securely when doing so remotely.

Budgets are also likely to have been reduced due to the uncertain economic climate, which further exacerbated the problem, Matsubara said.

According to a study by Barracuda Networks, 40% of companies worldwide have reduced their cybersecurity budgets as a cost-saving measure due to COVID-19. Some 51% said their workforce lacked proper training on the risks associated with remote work, and 51% had seen an increase in phishing attacks.

“We had to adapt to the COVID-19 situation quickly … [and] from a technological perspective, many of us were not ready,” Koh said. He noted that cybersecurity required a balance between usability, security and cost.

threats

HackerOne 's Mickos noted that the outbreak forced organizations to realize that they were lagging behind in digital transformation and cloud migration .

About 37% in Singapore said the pandemic had pushed them to accelerate their digital transformation efforts, with 40% admitting they were forced to do so without being fully prepared. “The pressure it has put and is putting on security teams is enormous,” he said.

Koh also advocated for the need to simplify technology, which was currently too complex and difficult to manage. “We are asking everyone, including small and medium-sized businesses, to be responsible for their own cybersecurity,” he said. “It needs to be made simple so that everyone can take care of their own cybersecurity. Security needs to be there by default, not acquired by design.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS