HomeSecurityCybersecurity Reports: They Focus on Hackers and Espionage. But What Are They Leaving Out?

Cybersecurity reports: They focus on hackers and espionage. But what do they leave out?

Most of the reports published by the cybersecurity industry focus on high-profit espionage and state-sponsored hacking operations. However, they fail to highlight the threats to civil society. In doing so, they do not accurately portray the emerging threat landscape in cyberspace.


In a paper published in the Journal of Information Technology & Politics, a team of academics, including some of the biggest names in cybersecurity and the internet, analyzed 700 cybersecurity reports published between 2009 and 2019.The reports the academics compiled came from two types of sources: commercial threat intelligence providers (629 reports) and independent research centers (71 reports). In addition, the team examined data from AccessNow, a digital rights advocacy group, to understand the true nature of digital threats.

Cybersecurity reports

The research team, which includes Lennart Maschmeyer, Ronald J. Deibert, and Jon R. Lindsay, found that only 82 of the 629 reports, or about 13 percent, focused on a threat to civil society. Of those 82 reports, only 22 focused on risks to civil society, while the remaining 607 focused on hacking gangs operating in cyberspace, such as APT.

In contrast, most cybersecurity reports produced by independent research centers have focused on threats to civil society. According to Maschmeyer, Deibert, and Lindsay, this is because companies are driven by their own lines and the reports they issue serve various purposes, such as advertising, as well as other interests.

Cybersecurity reports

In other words, cybersecurity companies, chasing corporate and government contracts, are focused primarily on investigating cybercrime, financial espionage and sabotage of critical infrastructure, while neglecting threats to both individuals and society as a whole. High-profile threats targeting high-profile individuals are prioritized, while threats to civil society organizations, which lack the resources to pay for their own defense, tend to be ignored and completely excluded from these reports. Thus, those who need more accurate threat intelligence but are poorly informed are left exposed to such risks.

Cybersecurity reports

Furthermore, according to the researchers, since cybersecurity companies are behind the majority of the reports produced, this situation creates a bias towards the reports, which may affect the perception of both policymakers and researchers, while in the long term it may also have consequences for government policies, a state's national defense strategies, as well as academic work.

The best example of this theory, which the researchers published in June, is the 2016 U.S. presidential election. U.S. cybersecurity agencies expected nation-state entities to hack the campaigns, which they did, but most of the real damage was done through social media influence campaigns targeting civil society. These influence campaigns , which were allegedly carried out by Russians , targeted both individuals and society, surprising most researchers and policymakers. This did not fit with prevailing threat models that focus on the disruption of critical infrastructure and large-scale digital espionage.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS