Study, which has been ongoing for ten years, says there has been no progress in addressing the cybersecurity skills gap and the demand and supply problem of cybersecurity professionals.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Cybercriminals design and test email phishing attacks to bypass Microsoft email defenses with nearly a fifth (18.8%) of phishing messages reaching their targets.
Snake oil marketing tactics by cybersecurity vendors complicate organizations’ security stack and expand the attack surface, according to Egress cybersecurity hype report. 91% of decision-makers found it difficult to select cybersecurity vendors due to unclear marketing about their specific offerings.
Surveyed organizations reporting a 61% drop in ransomware attacks but the average cost of ransomware attacks remains high, even as study shows increasing complacency among organizations in keeping vital safety measures in place.
Cloud security firm Ermetic found that vulnerable identities and misconfigured environments on most AWS accounts expose 90% of S3 buckets to potential ransomware attacks.
Shadow code may pose a serious supply chain risk. Sampling 4,300 websites and applications ranked by traffic, researchers discovered that each website had an average of 12 third-party scripts and three fourth-party scripts.
Publishing platform Substack has disclosed a data breach that leaked nearly 700,000 user records after an unauthorized third-party exploited a security flaw.
Hackers injected malicious code into nearly a dozen 20 NPM packages with billions of weekly downloads in a software supply chain attack after phishing a maintainer’s account.
A very commonly used VoIP telephony system has been compromised via trojans snuck in through an open source component, and the supply chain attack puts over half a million global businesses at risk.
Vulnerable IT service providers are becoming entry points for supply chain attacks as seen in the recent attack on Wipro. The attack follows closely after Wipro CEO declares "security cannot be a show stopper for business priorities".










