Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Three Persistent Data Security Challenges Organizations Need To Address Now
Articles Attacks Business and Policy Cloud Security GRC Ransomware Security

Three Persistent Data Security Challenges Organizations Need To Address Now

Dilki RathnayakeBy Dilki RathnayakeAugust 28, 2023Updated:May 2, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Data Security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When it comes to cybersecurity, bad actors never stand still. As a result, neither can today’s security professionals, technology providers and data privacy legislators. Indeed, an attacker now needs just 102 minutes to begin to move laterally once they have compromised a single device. This puts organizations under the gun to not only identify threats but respond at record speeds to avoid security incidents and ensure compliance with stringent regulations.  

This article explores three of the top data security challenges that organizations face today and offers advice for mitigating security and compliance risks.

Ransomware

Ransomware continues to be a pressing threat to data security and data privacy for public and private organizations alike. Ransomware threat actors look to gain an initial foothold in a network, commonly via a vulnerable internet-facing system or weak application settings. Then they set out to hijack legitimate user credentials and move laterally across the network. Their goal is to compromise additional accounts and tools in order to encrypt as much sensitive data as possible to use as leverage in their ransom demands. 

The following ransomware trends present a high risk today: 

·   Ransomware is evolving fast — Lockbit 2.0 emerged in 2022, but soon after patches to defend against it were released, Lockbit 3.0 appeared. Other ransomware groups are quickly developing new strains that share commonalities with previously identified ransomware; examples include Black Basta and BlackCat. Ransomware actors are likely to continue working hard to stay one step ahead of corporate defenses. 

·   Ransomware is increasingly human-operated — It’s estimated that one third of ransomware attacks are now successful because of the presence of a human being behind the keyboard. 

·   Ransomware risk is compounding with double and even triple extortion — More and more ransomware attacks not only demand a ransom for a decryption key; they also threaten data leakage for double extortion. And anecdotal evidence indicates that triple extortion is on the rise: If an attacker obtains sensitive information of a victim’s business partner, they attempt to extort ransom from that company as well. 

The best way to address the threat of ransomware is to reduce the risk of an infection and ensure that you can respond to an attack before it kidnaps your data. Consider implementing a zero standing privilege approach to reduce the risk of privilege escalation, improve your ability to spot suspicious activity, and ensure you can promptly take action to shut down threats, for example, by deactivating the compromised account or ending the RDP session. 

Cloud data security

The COVID-19 pandemic accelerated cloud adoption. More than half (55%) of workloads are expected to be in the cloud by the beginning of 2024, and 97% of mid-size organizations and enterprises will manage a hybrid environment by the end of 2025. What’s more, there has been a 75% increase in multi-cloud customers since 2017. This shift is driven by many factors, from mergers and acquisitions to the desire to use best-of-breed products and avoid vendor lock-in. But the resulting increase in complexity presents significant business and data security challenges, with additional resources required to handle the more complicated compliance, data classification, auditing and reporting, and privacy concerns.

Ultimately, organizations must remember that responsibility for data security lies with them, not their cloud providers. To ensure that their cloud adoption is fit for the hybrid working era, they need a robust data classification process, a just-in-time approach to privileged access (in which access is granted only when it is needed and only for as long as it is needed), secure configurations, and active monitoring of changes and user activity to ensure that threats are identified and stopped in real time. 

More data privacy laws

At least 35 states and the District of Columbia in 2022 introduced or considered almost 200 consumer privacy bills in the US alone. This year we are seeing a host of U.S.-based data privacy laws coming into effect, including the California Privacy Rights Act (CPRA), the Colorado Privacy Act (CPA) and the Virginia Consumer Data Protection Act (CDPA). These regulations all mandate increased visibility and control over data. 

Organizations operating in Europe will also need to pay attention to the EU Cyber Resilience Act. Although it is expected to come into full force in 2026 at the earliest, it will begin influencing tech investment decisions and product roadmaps much sooner. In particular, industries with a long production cycle, like manufacturing, need significant time to find, test and implement solutions that will meet the new requirements. For example, manufacturers are required to undertake a cybersecurity risk assessment for any product that has digital elements, which can be a time-consuming task. In addition, the act gives companies only 24 hours to report an actively exploited vulnerability in one of their digitalized products — another good reason to start implementing appropriate security measures to ensure compliance with the act now. 

Conclusion

Organizations are facing these data security challenges amid a current tough economic outlook, but the stakes are higher than ever. It’s highly advisable to prioritize data discovery and classification, just-in-time privileged access along with zero standing privilege approach. These elements will help organizations mitigate the risks posed by rapidly evolving threats like ransomware, ensure data security across their hybrid workforce even in multi-cloud environments, and achieve and maintain compliance with strict data privacy legislation. 

Dilki Rathnayake
Dilki Rathnayake

Dilki Rathnayake is a cybersecurity content writer and the Managing Editor at Information Security Buzz, with a BSc in Cybersecurity and Digital Forensics. She is skilled in computer network security and Linux system administration. Dilki has also led awareness programs and volunteered for communities promoting best practices for online safety.

  • Dilki Rathnayake
    The new rules of war have no rules
  • Dilki Rathnayake
    AI Malware Arrives: Google Uncovers a New Wave of Adaptive Attacks
  • Dilki Rathnayake
    Out of Office, Not Out of Mind: Staying Cyber-Smart Over the Holidays
  • Dilki Rathnayake
    The Real Purpose of the UK’s Online Safety Act: An Expert Explains

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}