According to a report by State Auditor Thomas DiNapoli, cyberattacks are a growing threat to New York City's critical infrastructure, with more than 83 cases in the first half of the year.
See also: Veeam fixes a bug that allows backup infrastructure to be compromised

According to the report, the state faced more than 25,000 cyberattacks in 2022, a 53% over the approximately 16,400 attacks in 2016.
In the first half of the year, there has already been a nearly 73% increase in cyberattacks on critical infrastructure compared to the 48 recorded cyberattacks that occurred last year. Critical infrastructure attacks involve “systems and assets that are vital to the functioning of society, the economy and national security,” the report states.
According to the report, cyberattacks cost New York $775 million in 2022, adding to last year's national loss of $10.3 billion. New York had the third highest incidence of ransomware and corporate data breaches nationwide.
Last year, there were attacks in New York against critical infrastructure, which included nine incidents in the healthcare and public health sector, eight incidents in financial services , and seven incidents in both commercial and government facilities.
Some of the widespread weaknesses in New York City's cybersecurity identified in the report include a lack of understanding of security risks, use of unsupported applications, lack of knowledge about data in systems, inadequate access control, and lack of monitoring of system changes.
In May, the Albany NanoTech Complex was hit by a ransomware attack that disabled email. The building is home to SUNY Polytechnic University's College of Nanoscale Science and Engineering and the state's microchip research center.
The state's ethics commission also fell victim to a "malicious cyberattack" in February 2022, when a web server hosting the state's lobbying registration and financial management systems had to be disabled.
See also: Barbie and Oppenheimer: The release of blockbusters led to cyberattacks

DiNapoli's report also clarified that local governments and school districts face particular risk from cyberattacks, as audits from 2019 through July reported more than 2,400 cybersecurity issues in infrastructure.
The report recommends improving IT security awareness through training and establishing contingency plans, which can be implemented at minimal cost.
Some measures that can help address this issue are:
- Staff training: Staff managing critical infrastructure must be well-informed about cybersecurity to reduce risks and effectively protect data.
- Implementing technological solutions: Advanced technological solutions can provide significant assistance in the fight against cybercrime. tools offer increased protection and responsiveness.
- Create emergency action plans: A crisis response plan can significantly mitigate the effects of a cyber-attack, ensuring the restoration of infrastructure functionality in a short period of time.
With education, the adoption of continuously evolving technologies, and well-designed emergency response plans, we can do our part to effectively address cybercrime.
Last year, Gov. Kathy Hochul appointed a chief cybersecurity officer, Colin Ahern, to strengthen cybersecurity across all government agencies. Ahern directs the Joint Security Operations Center, which connects state government with New York and other local governments to improve detection and response to cyberattacks.
In August, Hochul also released the state's first cybersecurity strategy, paving the way for federal funding for the issue.
Last year, the federal government took action by passing the Critical Infrastructure Cyberattack Reporting Act, which would require reporting of cyber threats for sectors considered “critical infrastructure.” The report states that including local authorities in this reporting would improve coordinated responses to cyberattacks at the national level.
See also: SEC: Companies must report significant cyberattacks within 4 days
From espionage and cyberwarfare to financial incentives, the rise of cyberattacks on critical infrastructure is diverse and complex. The main reasons why these cyberattacks are possible are:
- Inadequate Data Protection: While it may sound unbelievable, many times the reason is simply poor data protection. Increasing attacks show that compromised systems are full of vulnerabilities that allow attackers to get in. It’s like leaving the door to your house open while you’re on vacation – and then wondering why thieves broke in!
- Advanced Actors : Cybercriminals are constantly evolving, using technological advancements and easily accessible tools to commit their crimes.
Source: timesunion
