In recent years, misinformation has increased significantly, but so far it has been treated simply as a challenge for technology, including social media platforms. However, because misinformation is by nature an online risk, it is also a challenge for the cybersecurity ecosystem.

However, it is not so easy to effectively combat misinformation. With the vast amount of information out there, it is difficult to distinguish the truth from the lies. From the destruction of 5G towers to conspiracies like QAnon, distrust is becoming the default, and this can have incredibly harmful effects on society.
Misinformation and fake news can also be used to spread malware by manipulating people’s fears. For example, Avast found that fake stores claiming to sell Covid -19 using the World Health Organization logo were intended to trick people into downloading malware.
So far, the tech sector, and especially social media, have tried to implement some measures, with varying levels of success. For example, WhatsApp has set a stricter limit on the ability to forward messages and Twitter has started to flag misleading posts.
Despite these efforts, reports highlighting concerns about the issue from intelligence agencies and independent committees are often overlooked, while policies cannot be implemented quickly enough to keep up with the ever-changing ways in which fake news.

Furthermore, disinformation has the potential to undermine national security and must be at the core of our cyber defenses.
However, the cybersecurity innovation ecosystem as a whole is often under-incentivized to play a role in this landscape. Many companies have the tools to combat disinformation and take down botnets, such as automated threat detection, but they don’t see tackling disinformation as their domain.
This will change as businesses increasingly become targets of misinformation.
Disinformation continues to be an emerging cybersecurity risk, and we will need unconventional techniques beyond data breach notifications and regulatory fines. New alliances and partnerships between industry and government must emerge. The first step, then, is to recognize disinformation as a new type of online risk, where effective cybersecurity is part of the solution.
