Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Cyberattacks In An Evolving Landscape – Should Businesses Be Worried?
Study & Research

Cyberattacks In An Evolving Landscape – Should Businesses Be Worried?

ISBuzz TeamBy ISBuzz TeamFebruary 12, 2018Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The threat landscape is evolving and with attacks becoming more sophisticated, every business, no matter its size or the industry it’s in, is at risk.

According to Microsoft, the potential cost of cybercrime is $500billion, with data breaches costing the average company approximately $3.8million. While the potential financial impact is eye-wateringly large, these costs are only set to grow. It is predicted that the average cost of a data breach will exceed $150million by 2020 and by 2019, cybercrime will cost businesses over $2trillion.

This isn’t good news for businesses, especially now the days when a firewall alone was sufficient protection against cybercriminals are over. New technology in the workplace, along with complex partner ecosystems and flexible working practices, have changed the boundaries of enterprises for good. Attack actors have taken advantage of those who haven’t kept up with the pace of change.

Here are a number of ways those with malicious intent are attacking organisations and the threats businesses need to be particularly aware of as we enter 2018.

Nation state attacks

Nation state attacks are commonplace these days. Just take the Russian agencies using cyberattacks to extract information in a bid to influence the US presidential election, the Petya attack, and also WannaCry malware – two attacks often attributed to state-sponsored hackers.

Using WannaCry (which has one of the largest attack vectors to date) as an example, it has raised some interesting points around the psychology and the tasking of nation state hackers. When released, it was unclear who was behind WannaCry and while the malware used the same wiper software as Lazarus had previously implemented in other attacks attributed to nation state actors, its presence cannot be taken as attribution in the classic sense. The similarities in attack vectors may have suggested the same operators were involved in both attacks, but the intended effects seemed to be quite different. With this in mind, it was unclear whether this represented a multi-faceted nation state portfolio of attacks, covering multiple intended effects, or whether it was simply a reuse of previous capabilities by a hacker group that had formerly operated on behalf of a nation state attack.

It has since been confirmed by both the UK and US governments it’s “highly likely” that WannaCry was caused by Lazarus. However, with attribution difficult and it almost impossible to identify patterns in behaviour that could prevent future attacks without deep insight into how operator groups are tasked by their benefactors, nation state attacks continue to pose a threat to organisations.

Cyber vandalism

Cyber vandalism has been identified as a major part of the evolution of the cyber threat landscape, having become popular with threat actors across the world.

Despite this increased popularity though, it’s often difficult to understand the reward for threat actors staging this form of attack, as well as the motives behind them. Perhaps it’s a student wanting to show off their cyber skills, or maybe a developer testing their latest malware creations?

However, there is good news for organisations looking to battle cyber vandals. In fact, with more data available than ever before, it’s now possible to identify changes in attackers’ approaches which better allows businesses to protect themselves from becoming a target.

While taking the time to stop and think about the actor behind these attacks may seem like a luxury, it’s vital for enterprises to start looking at cyberattacks from the adversary’s perspective to understand what attacks are more attractive and lucrative to the actors and understand how best to protect against them.

Third-party attacks

More businesses are joining forces with, and benefitting from, partnerships with third-party suppliers. A survey by Thompson Reuters into third party risk revealed that 70 per cent of organisations have become more flexible and competitive because of third-party relationships.

Despite the obvious benefits of adding organisations to a supply chain, businesses often forget about the security vulnerabilities this opens them up to.

Threat actors are able to exploit any weakness in a supply chain, targeting the smaller (and potentially less secure) enterprises and using them as a stepping stone to the larger businesses within the chain. These kinds of attacks mean it’s no longer enough for organisations to understand just their own security set-up – they need an overall picture of the security of their entire partner network. 

Also, the General Data Protection Regulation (GDPR), Open Banking and the Second Payment Services Directive (PSD2) are all on the horizon, making it even more critical for organisations to know and understand their entire ecosystem. By undertaking regular overarching audits and turning this into a mandated process throughout the supply chain, businesses can do just that, as well as foster good threat intelligence sharing regimes in a bid to protect against third-party attacks.

Alongside this, every single organisation within a supply chain needs to be equally aware of and protected against this form of attack. The best way to do this is by working closely together to implement an overarching cybersecurity strategy throughout any partner network.

As the threat landscape continues to evolve and new and more complex attacks become commonplace, it’s vital to the success of a business that enterprises act now to safeguard their information against attack actors. By ensuring the relevant cybersecurity strategies are in place, organisations can rest safely in the knowledge that they are protected against modern threats.

[su_box title=”About Chris O’Brien” style=”noise” box_color=”#336588″][short_info id=’104394′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}