Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Ukraine Conflict Puts Organisations’ Cyber-Resilience To The Test
Articles

Ukraine Conflict Puts Organisations’ Cyber-Resilience To The Test

Julia O’TooleBy Julia O’TooleMarch 9, 2022Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Former FBI Agent Urges Cyber Discussions with Russia
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Julia O’Toole, founder and CEO of MyCena Security Solutions,urges businesses to bolster their cybersecurity to avoid getting caught in the cyber crossfire of the Russia-Ukraine conflict.

Russia’s invasion of Ukraine has provoked a massive rally of hackers to join both sides of the conflict and take up arms in the cyber-war. As has been the case in cyberattacks of recent years, the consequences of this will affect organisations way beyond the initial intended target. For example, in June 2017 French company Saint-Gobain was forced to halt its operations as a result of the NotPetya attack, a Russian cyberattack targeting Ukraine that resulted in over €80 million of losses in company revenue.

As a result of a sharp increase of cyber-attacks since the beginning of the conflict, from DDoS, new data wipers, phishing campaigns and malware, organisations worldwide should take immediate action to improve their cyber-resilience and limit the damages that any spillover could have on their business.

The influx of inexperienced cybercriminals creates a new sense of vulnerability for both businesses and citizens. With IT and OT/ICS highly connected to critical infrastructure, the impacts of a cyberwar will be wide reaching and potentially devastating.

In the last 18 months, we have seen water plants and oil pipeline systems breached, luckily without mass poisoning or infrastructure explosions. But where nation-state hackers may show restraint, “freelancing hackers” may not. With heightened cyber-risks, there is an urgent need for organisations to become cyber-resilient. And this needs to start with recognising why cybersecurity has not worked in the past.

Common cybersecurity weakness

The primary reason why it is so easy for criminals to take command and control over a network is because there are inherent weaknesses in the traditional approach to network security.

In a physical environment, organisations distribute keys to the employees, not the other way around. But in their digital environment, organisations let employees create their own keys, blindly transferring power of control to their employees. Employees can share, lose, reuse their passwords without organisations knowing if and when that happens. Nine times out of ten, criminals don’t need to hack in, instead they log in, using tactics like phishing, social engineering, credentials stuffing, password spraying. In fact, password phishing was responsible for 83 per cent of all cyberattacks in 2021. And having employees regularly changing their passwords from DomSmith123! to Dom$mith1234 or any other variation after a cyberattack will not stop a malicious actor from logging in again.

Organisations are not only losing the battle for command and control. They have also made it easy for criminals to maximize the impact of any breach by centralising access behind a single door. After escalating privileges to a local or domain admin, criminals can take control of the whole network. Once inside a network, they can ‘stay and spy’, install data wipers, lock files, halt operations, and launch a ransomware attack.

Current cybersecurity strategies that only prioritise network perimeter security with investments focused on detection, response, patching and crisis management, have also been ineffective by design. In the same way that you can’t spot a new COVID variant before it is circulating, it is mechanically impossible to fix vulnerabilities before they are discovered, meaning it is impossible to prevent cyberattacks or zero-days.

Ransomware attacks also work to prolong the conflict through funding further cybercrime. According to a report by Chainanalysis, nearly three-quarters of traceable ransomware revenue in 2021 (around $400 million worth of cryptocurrency) was laundered through Russia. After removing selected Russian banks from the SWIFT system and freezing their central bank assets, cryptocurrency gained through ransomware could offset the financial sanctions and help sustain Russia’s army for longer.

Protect network access and ensure cyber-resilience

Organisations urgently need to regain command and control over their networks and enhance their cyber-resilience. This requires an overhaul of the approach to security.

The fundamental change required is to apply physical access security rules to their network. Firstly, don’t let employees make and share their own passwords. Secondly, don’t aggregate all systems behind a single door with one key that can open everything, instead segment system access. That way, if one password is stolen while others remain out of reach, a breach is contained by default. And finally, ensure all passwords stay encrypted from end-to-end, during creation, distribution, storage and use, so that no one can see, share, or phish them. Using a zero-trust, credentials-based system means that only a legitimate user can access their credentials through multiple levels of security.

It is not too late to make digital infrastructure cyber-resilient with access segmentation and security. Organisations must now take responsibility for the security of their own networks, or risk getting caught in the cyber crossfire.

Julia O’Toole

Julia O’Toole, Founder and CEO at MyCena Security Solutions

  • Julia O’Toole
    Ukraine Conflict Puts Organisations’ Cyber-resilience To The Test

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}