Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How Can Organisations Protect Themselves From Cyberattacks In An Increasingly Virtual World?
Articles

How Can Organisations Protect Themselves From Cyberattacks In An Increasingly Virtual World?

Matias MadouBy Matias MadouMarch 1, 2022Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
E-Series Solutions
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Research by McAfee discovered that 81% of global organisations experienced increased cyber threats during the Covid-19 pandemic. This threat has also extended to the public sector, and has become a significant enough concern to prompt the UK government to launch the nation’s first ever cybersecurity strategy to help protect public sector bodies from bad actors. A Cyber Coordination Centre is also being set up, with the aim of transforming the sharing of data and cyber intelligence.

Following major incidents such as the cyberattacks on SolarWinds and Microsoft Exchange Servers, the UK government is going further by taking steps to introduce new measures to enhance British business cybersecurity. Additionally, ransomware threats have impacted on critical national infrastructure, with a major example being the Colonial Pipelines attack in the United States.           

With the immediate need to work virtually due to the pandemic, cybersecurity posture among organisations was truly tested, and prompted businesses to step up their cyber strategies, such as code-level software security. Measurable security awareness and the need to adopt a preventative mindset is now crucial, and there are several emerging technology areas where cybercriminals are now starting to target.      

The metaverse threat

The metaverse may well be the exciting future evolution of the internet, based in persistent, shared virtual worlds in which people interact as 3D avatars. However, a similar transformation is yet to materialise in the way most industries approach securing software and digital environments.

Infrastructure and devices around these new immersive virtual worlds will need to be made secure. Virtual reality (VR) headsets are the new gateway to huge mountains of user data. Complex embedded systems security is required to make Internet of Things (IoT) gadgets safe, and the brave new world of mainstream VR and augmented reality (AR) are no exception. As with the Log4Shell exploit, simple errors at the code level can bloom into a backstage pass for cybercriminals, and in a simulated reality, every movement creates data that can be stolen. 

With the metaverse in its early stages, its success will hinge on practical adoption of cryptocurrency. Non-fungible tokens, known as NFTs, mean our real-life wealth, identity, data, and livelihoods are potentially opened-up to a new “Wild West” that can put people at risk. Minimising this new, vast attack surface from the ground up should be a priority.

The Log4j attack

The zero-day attack on the Log4j logging tool was reported to be among the worst on record with comparisons made to the devastating Heartbleed OpenSSL vulnerability that is still being exploited over six years later. The aftermath of Log4Shell is also likely to last for a long time. It’s a lesson that many organisations just don’t act swiftly enough to protect themselves. Depending on their size, patching can be incredibly difficult and bureaucratic, requiring cross-department documentation and implementation. Quite often, IT departments and developers don’t have an encyclopaedic knowledge of all libraries, components, and tools in use, and are hamstrung by strict deployment schedules to minimise disruption and application downtime.    

While there are already patch management mandates and recommendations in some critical industries, widespread legislation is another story. Preventative software security will always be the best chance to avoid urgent security patching altogether, but best practices dictate that patching is non-negotiable and should be a priority measure. This will be a hot topic, and lead to not-so-subtle recommendations to patch quickly and often.

Focus needs to be placed on architectural security

Significant additions were included in the recent Open Web Application Security Project (OWASP) Top 10 report, including injection vulnerabilities, which fell from first to third place. The new additions reflect a new stage of a developer’s journey in secure coding and security best practices, but most unfortunately remain unequipped to reduce risk due to a lack of appropriate training.

Developers need to be fully skilled in security to battle against common code security bugs. More businesses are taking this challenge on with developer-driven prevention. Despite this, Insecure Design, otherwise expressed as “missing or ineffective control design,” is in the OWASP Top 10 and is characterised by architectural security issues rather than a specific security bug. Developers will need to be encouraged to go beyond the basics once they’ve mastered them.    

It’s vital that developers are informed about threat modelling and the security team should also be supporting, which will help to take the pressure off them once developers are skilled in this area. As it stands however, it’s still a knowledge gap for software engineers. The onus is on the rest of the organisation to help create a positive security culture for developers.

Matias Madou

Co-founder and CTO

  • Matias Madou
    Adding A Human Firewall: The Role Of Developers In Protecting The Supply Chain
  • Matias Madou
    How To Become A Kick-Ass DevSecOps Engineer
  • Matias Madou
    Why SQL Injections Are The Cockroaches Of The Appsec World (and how CISOs can eradicate them once and for all)

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}