Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - The evolution of cyber risk: Addressing geopolitical threats
Critical Infrastructure Security Articles Attacks Data Protection Evasion Attacks Identity & Access Management Security

The evolution of cyber risk: Addressing geopolitical threats

Avani DesaiBy Avani DesaiMay 13, 20265 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Addressing geopolitical threats
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Ransomware, data breaches, phishing schemes—cyber attacks can take many forms. Traditionally, the motive of these attackers can often be traced back to some sort of tangible goal. An attacker may want to extort some financial gain from a business, while another may seek to gather sensitive information to commit other crimes, like fraud.

Any breach or lapse in security can lead to potentially devastating regulatory fines, lost resources, repair costs, or even irreparable damage to a brand. Fortunately, in these cases, security teams still have the advantage of understanding what an actor might do or is planning to do based on those goals. Patterns emerge and security professionals can take steps to mitigate risks and deter attackers from going after their business.

For business leaders, it’s a frightening prospect. An IBM report found that the cost of a single data breach can soar well beyond $4 million. And now, the cybersecurity landscape is only getting more fraught with danger and more complex. 

The current geopolitical landscape presents a completely different reality: damage and destruction as the goal, not monetary gain.

What do you do when there’s an attacker that sets its sights on your organization to do nothing more than cause maximum destruction and chaos?

Today, with critical infrastructure and other sensitive systems in the crosshairs of state-level actors, the traditional enterprise risk model, primarily aimed at ransomware and data theft, falls short.

Risk modeling level up: The geopolitical threat

How do you beat an attacker who has no motive? If an attacker gains access to your systems, there is no guarantee that any payment will make them relent. Answering this question is something that must be at the top of every CISO’s to-do list.

Oftentimes, these kinds of attacks seek to gain access to critical infrastructure, whether that’s a power grid, water supply, or a government agency’s most sensitive data. And while a business may not appear directly connected to these systems, any government contract, third-party vendor, or business relationship could put them squarely in the crosshairs of a geopolitical attacker.  

It’s a reality that more organizations are becoming aware of and troubled by. A survey from the World Economic Forum (WEF) found that 65% of respondents said their greatest challenge to achieving cyber resilience was supply chain and third-party vulnerabilities. Further data from a Verizon report on data breaches found that the percentage of breaches where a third party was involved doubled from the previous year.

This is where the biggest shift in risk modeling needs to happen. Traditionally, the focus has been on where weaknesses exist within an organization’s operations. Now, that assessment needs to account for every factor up and down the supply chain, even stretching to the smallest business partnership—every dependency matters. It’s in these dependencies that weaknesses in security elements like identity and access management (IAM) can arise. 

And this is where we arrive at one of the most important components, IAM and the management plane.

Stopping a lurking threat starts with robust access controls

Among the dependencies that pose a threat to security teams, IAM and control of the management plane rank as one of the most crucial. Large organizations have a set of credentials and access permissions that are constantly in flux. Someone who needed access one day may no longer be needed the next.

Likewise, third-party vendors come and go. If those access controls are not strictly monitored, reassessed, and revoked as needed, something as simple as a faulty password or a simple phishing scheme could be enough to let an attacker in.

As organizations reorient themselves te cyber threats that seek to cause chaos for its own sake, success depends on absolute control of the management plane. Step one in building that control is to reshape how access is handed out. In short, it can’t be left to an understaffed IT department.

Security teams need to put extra emphasis on tasks such as continuous credential validation, a comprehensive review of standing permissions—who needs them, who has too much access, and who needs to be removed—and policy shifts to restrict the total amount of permissions and privileges as much as possible. This is particularly important in the context of third-party organizations where engagements may be short with less-known individuals granted access across systems.

A future defined by global threats

The days of paying off an attacker to get your data back or systems back online are quickly fading. That’s not to say ransomware and other financially-motivated attacks are decreasing by any means. The reality is that security teams must account for far more motives, or rather, a lack of a motive altogether. In this scenario, if an attacker gains access, there’s little that will deter them from tearing down everything in sight.

Addressing threats on a geopolitical scale will require alignment from the boardroom down to the security practitioners tasked with keeping systems safe. But more than that, organizations must fundamentally rethink what it means to be prepared. Traditional playbooks centered on detection and response are no longer sufficient in a world where disruption is often the endgame.

Building resilience in this context will mean designing systems, access controls, and operational processes with the expectation that a breach will occur and that the attacker may have no incentive to stop.

Avani Desai
Avani Desai

Avani is Chief Executive Officer at Schellman, the largest niche cybersecurity assessment firm in the world that focuses on technology assessments. Avani is an accomplished executive with domestic and international experience in information security, operations, P&L, oversight, and marketing involving both start-up and growth organizations.  She has been featured in Forbes, CIO.com, and the Wall Street Journal, and is a sought-after speaker as a voice on a variety of emerging topics, including security, privacy, information security, future technology trends, and the expansion of young women involved in technology.

  • Avani Desai
    https://informationsecuritybuzz.com/author/avani-desai/
    Strengthening Security Fundamentals During High-Risk Periods

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

April 20, 20266 Mins Read

Eurail User Records Up for Sale on the Dark Web

February 18, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}