enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

LPL Financial

Foreseeing The Cybersecurity Scenario In 2022

Justin Anderson, Manager - Cyber Threat Intelligence, LPL Financial

Predicting what will happen in the coming year is difficult. However, the previous year may help organizations strengthen their cybersecurity posture and add chapters to a CISO's best practices playbook.

FREMONT, CA: From a CISO's perspective, 2021 was a challenging year. Businesses may anticipate more new twists in the year ahead. Examining the hacks that CISOs have been forced to deal with, either directly or indirectly, and the trends and concerns that have emerged can assist companies in forecasting what to expect in 2022.

Ransomware: Ransomware is here to stay. According to one report, approximately 500 million ransomware attacks were attempted by the end of September in 2021. By the time the ball descends on New Year's Eve, that figure should be closer to 700 million. Ransomware assaults against the financial industry alone were more than 1,300 percent.

Perhaps no ransomware attack garnered more attention than the one on Colonial Pipeline, which gave Americans their first taste of how damaging cyberattacks on crucial infrastructure can be. Even while this attack targeted Colonial's financial operations, it effectively halted oil delivery to the eastern portion of the country, causing widespread panic.

Colonial Pipeline's attack could have been considerably worse, as were the ransomware attacks on Kaseya (which compromised the IT infrastructure of some of the world's largest firms) and JBS Foods. Businesses don't know how these attacks contributed to current supply chain difficulties, but they undoubtedly contributed. They are never more than one attack away from a breach that would bring the electricity grid or food supplies to a halt for an extended period. The only effective method to avoid this is to use tools that regularly monitor and assess an organization's ransomware susceptibility.

Cloning of websites: While much of this year's attention has been focused on ransomware, one of the trends businesses will be peering more closely in the coming year and beyond is website cloning and online fraud issues. Cyberattacks perpetrated from abroad defraud both consumers and brands. The fraudsters target well-known brands in the United States, whether they be banks, significant technology businesses, or even cryptocurrencies, hoping that the consumer will be ignorant that the link they are clicking takes them to a clone of the legitimate website. Convinced that they are on the correct website, the customer submits their log-in and other personal information, resulting in credential theft, account takeovers, and increased headaches as credential stuffing attacks spread.

Combating website duplication demands a proactive approach. CISOs will need to leverage cybersecurity capabilities to detect and shut down scams before they reach consumers, employees, or other online users.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.