Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cybersecurity and Geopolitics are Twisted
Articles

Cybersecurity and Geopolitics are Twisted

Ilia KolochenkoBy Ilia KolochenkoAugust 12, 2015Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

What is the relation between growing security spending, increasing hacking attacks and falling economy?

Have you ever thought how the global economy and geopolitics influence cybersecurity and cybercrime? Some people may think these are two completely different domains, however they are strongly and permanently related.

An interesting example came up during our recent security awareness project at a large, Central European financial institution. The institution was concerned about a significant increase in hacking attempts that involved social engineering and spear phishing campaigns.

The security awareness training for all of the employees was validated with a social engineering attack against all employees to check if they had learned any lessons. Only a few people from the board were aware of this test. The attack scenario was quite simple: a local lottery announced that the employee has won a big sum of money. The results were pretty much common for the European financial industry, besides one curious outcome in the analytical report: 87% of newly-hired employees, including experienced seniors and even a member of the IT security team, clicked on the link in a phishing email. Among “old-school” employees, who were hired a long time ago, and had worked in the financial institution for many years, the click-rate was only 11%.

Infosec spending not keeping pace : 

Let’s have a look at the numbers to get a clearer picture of what is actually going on. Gartner says that worldwide information security spending will reach $71.1 billion this year, almost an 8% growth in comparison to the last year, as “organizations become more threat-aware”. Meanwhile, the cost of global cybercrime is about $445 billion per year, a 33% percent growth according to McAfee. Common sense suggests that something is definitely wrong here, as we cannot increase spending while at the same time observe our losses from cybercrime increasing. Let’s try to understand what is going on from the economic point of view.

I regularly meet information security managers and CSOs from midsize to large companies. Among many of these companies, there has been a certain reduction in information security spending in comparison to previous years, especially to acquire new solutions and products. Some respectable financial companies I know are even returning to paper for top secret documents. One of the largest NGOs in Geneva has recently re-introduced typewriters for their confidential documents, as they simply don’t trust digital storage anymore. Companies are losing trust in the information security industry, feeling it incapable to protect them. Why does it happen?

While the financial markets are falling, investors are looking for new financial instruments to make quick money. Risky bonds are becoming even more risky with the falling economy, and not many investors are ready to burden such risks. Where do they go? Well, many of them go to the cybersecurity market, as it’s a very hot topic today. The problem is that there are very few really innovative cybersecurity companies that invent conceptually-new approaches to solve effective problems of their customers in the most efficient way.

Many cybersecurity start-ups consider that reinventing a security scanner with a different GUI, report format or pricing model is enough to compete. The problems is that we just don’t need one more vulnerability scanner – we already have enough. We need a new concept, a new innovative approach to security testing. And very few companies have visionaries capable of creating such concepts. Nevertheless, they manage to raise funds from desperate investors trying their luck in the cybersecurity marketplace.

Last, but not least – spending more on average per year doesn’t mean that people are buying new solutions and becoming “threat aware”. The increase is also influenced by the increasing number of devices (e.g. mobiles) for which companies start buying security software they use on desktops to synchronize everything. Sometimes cybersecurity spending is just following the volume in corporate IT spending.

Let’s switch to cybercrime. Cisco estimates that there is a million unfilled security jobs worldwide. Meanwhile, Internet  XSS archive received over 20,000 submissions of vulnerable websites in its first year, including companies that have Bug Bounty programs such as LinkedIn, eBay or Amazon. Something is not quite right again here.

Are we sure that the problem we face is a lack of skills, and not in fact that there are too many barriers stopping talented young people from developing countries applying their skills in developed countries? Smart graduates from developing countries may expect a very modest salary in their home countries, while emigration to developed countries is a pretty difficult, expensive and time-consuming process. Should we expect these skilled people to sit idly by, respecting the letter of international law that prevents them from experiencing a much better standard of living?

Of course not – they have in many cases adequate technical skill and tools to earn considerable sums as Black Hats, while evading detection. I am not talking about beginners who rely on simple evasion methods like TOR and open proxies, but about professional hacking teams that devote a significant part of their budgets to remaining anonymous. Even the Grey Market brings huge money in comparison to what can be gained from the most generous Bug Bounty.

If society is unable or unwilling to provide these people with well-paid jobs to protect our infrastructures, we should expect to see them on the other side of barricades soon, breaking into our corporate networks and generating more news about APTs.

Should we persist in trying to combat cybercrime using a technology only approach, and not take into account the effect of economics and geopolitics, we will continue losing the most important battle of the 21st century.

Before rushing to a conclusion, I would like to highlight that the financial institution in question has never performed security training on such a large scale before. The internal conclusion was pretty quick and straightforward: corporate culture persistently encouraged financial prudence among all employees, and therefore the employees were used to this culture and embraced it wholeheartedly, becoming more careful in general than their newer colleagues.

Conclusion : 

Almost all newly hired employees, regardless of their position, skills, seniority and experience, were paid much less than their colleagues hired years ago with generous salaries, when our society was not aware of Grexit, Brexit or PIGS. Obviously, the newer money-hungry employees were more likely to fall victim to this sort of phishing, as they dreamed of paying off the house mortgage or car leasing. The newer employees wanted to believe that this phishing email was genuinely a lottery win, as no security trainings can change the fundamental psychology and economic needs of people. Think about it, I’m sure you’ll find many similar cases in your daily infosec practice.

[su_box title=”About Ilia Kolochenko” style=”noise” box_color=”#336588″][short_info id=’60198′ desc=”true” all=”false”][/su_box]

Ilia Kolochenko

Ilia Kolochenko is a Swiss application security expert and entrepreneur. He started his career as a penetration tester and has 15 years of experience in security auditing and digital forensics. After serving in Swiss artillery troops in 2007, Ilia founded his first pentesting and cybersecurity consultancy High-Tech Bridge. In 2014, Frost & Sullivan named the company a leading service provider in the European pentesting market. Later Ilia invented and built the concept of the ImmuniWeb Platform, which combines the strengths of human intelligence with Machine Learning, and is now entirely dedicated to it.As a Chief Architect at ImmuniWeb, he leads our data scientists, security analysts and software engineers. Ilia holds a bachelor degree in Computer Science and Mathematics from Webster University, a Master of Legal Studies from Washington University in St. Louis and a Master of Science in Criminal Justice (Cybercrime Investigation) from Boston University. Currently, Ilia is a Doctoral student (Ph.D. in Cybersecurity Leadership) at Capitol Technology University. Ilia Kolochenko is a member of Europol Data Protection Experts Network (EDEN), a Member of GIAC Advisory Board and a Committee Member at Boston University MET CIC (Cybercrime Investigation & Cybersecurity) Center. Ilia is a certified GIAC GLEG professional (Law of Data Security & Investigations) and a Certified Information Privacy Professional (CIPP/US and CIPP/E) by IAPP.

  • Ilia Kolochenko
    Japan Hit By Another Cryptocurrency Heist – $60 Million Stolen
  • Ilia Kolochenko
    Web Application Firewall: a must-have security control or an outdated technology?
  • Ilia Kolochenko
    How to Calculate ROI and Justify your Cybersecurity Budget
  • Ilia Kolochenko
    Hackers Break into Businesses’ Websites and Apps

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}