Tackling cyber threats in the post-pandemic era

Issue 8 2021 Information Security

Cybercrime costs are expected to increase by 15% each year over the next five years, reaching US$ 10,5 trillion by 2025. Threats like phishing, malware and ransomware attacks disrupt businesses, crush economies and even destabilise governments.

Remember the ransomware attack on Colonial Pipeline halting operations for six days, fomenting a severe fuel crisis and price spikes on the east coast of America for a week? Attacks like these have targeted industries as diverse as IT, healthcare, education, finance and logistics. The pandemic marked a significant rise in attacks on the cyber landscape with the integration of IT and operational technologies resulting even in critical infrastructure industries being targeted.

Nobody is safe

Cyber-attacks have targeted big enterprises like JBS, infiltrated Florida’s water supply and has exploited vulnerabilities even in Microsoft’s Exchange Server. With large enterprises keeping a keen eye on cyber-attacks and setting up dedicated teams and allocating resources to ensure cyber safety, attackers have shifted their focus to small and medium-sized businesses.

This is alarming on multiple levels. The most notable being the frightening statistic that 60% of small companies go out of business within six months of cyber-attack. SMBs normally lack the resources for handling cybersecurity or the ability to provide dedicated IT support and increased attack vectors are being targeted at SMBs, often jeopardising the businesses. With the pandemic, the evolution of hybrid work as a norm and the increased adoption of Bring Your Own Device (BYOD), attack surfaces have increased significantly.

Maintaining cyber health

According to Verizon’s 2021 Data Breach Investigations Report (DBIR),22% of data breaches involve phishing. According to Terranova Security’s ‘Gone Phishing Tournament,’ phishing email links get clicked by 20% of employees and almost 67,5% of employees provide their credentials on phishing websites. And one in 10 people even clicks on phishing links on mobile phones. Users need to be vigilant in clicking random links since phishing might lead to malicious websites and can steal critical data and information.

The essential awareness on not to click random links exists among users. However, discerning the legitimacy of an email is easier said than done, there are no explicit hazard signs unless you’re specifically prepared for them.

With most, if not all, services adopting a cloud-based model, clicking on an array of links for varied purposes is nothing unusual at a workplace. As a result, mandating the employees not to click on any link may be counterproductive and leave room for confusion and requires a lot more nuance.

One technique enterprises can use is to block known malicious email domains altogether, or only allow emails from trusted sources. There’s also an argument for a degree of cyber safety education, such as always checking the ‘sent from’ address on an email to make sure it actually matches the person requesting you click on a link or provide specific information.

Equipping the workforce to identify when they have clicked on something undesirable and to enable them to report it to the IT team is equally essential. Unfortunately, only a small percentage of companies are capable of identifying an attack in its early stages.

Nordpass, on analysis of passwords used at Fortune 500 companies, discovered that the companies were using passwords that could be hacked in less than a second. Maintaining a strong password is an often-overlooked elementary strategy to ensure data safety. It should be mandatory to train employees on the necessity to establish and maintain secure passwords.

Corporates need to enforce password policies like multi-factor authentication, using longer passwords with complex characters and changing the passwords frequently. Password managers can help generate strong passwords and store complex passwords separately. Various password managers like Keeper Security, Last Pass and 1 Password are leveraged by enterprises.

Legacy systems that employ outdated hardware/software are often prone to cyber-attacks since such systems lack the latest patches against new vulnerabilities and can’t incorporate the latest practices for cyber security.

The 2017 WannaCry attack exploited Microsoft’s end-of-life (EOL) for Windows XP. Enterprises that used Windows XP did not install the patch that could fix a vulnerability called EternalBlue. Since Windows XP reached the end of life in 2014, the OS lacked technical and security updates. Microsoft’s Windows XP, released in 2001, is still running on many desktops and laptops worldwide. Employing an EOL Operating system can cause security issues, growing maintenance costs and compliance and legal hassles.

Understanding cybersecurity and the way forward

Gartner predicts that by the end of 2023, more than 50% of enterprises will replace older antivirus products with combined Endpoint Protection Platforms (EPP) and Endpoint Detection and Response Solutions (EDR). EDR can detect advanced threats and malware that can get past conventional security architecture.

With the pandemic accelerating remote work at unprecedented levels, conventional strategies like firewalls, VPNs that create a perimeter around the network are no longer sufficient to safeguard the enterprise. A Zero Trust model removes implicit trust and ensures that no user is trusted by default. The Zero Trust model leverages micro-segmentation and organisations can secure corporate data by enforcing granular policies by role-based access. A Zero-Touch Network Access (ZTNA) grants access to specific applications and services employing encryption preventing users from accessing other services.

Complete visibility into the corporate assets

Managing the enormous volume of endpoints spread across diverse geographic locations is a challenging task for businesses. Unified endpoint management solutions are used by enterprises to manage varied endpoints like PCs, smartphones and IoT devices from a centralised console.

With remote work and BYOD, UEM solutions have gained significant prominence in businesses. In a normal scenario, businesses would have had difficulties or a time lag in facilitating new approaches. But the pandemic forced businesses to look for and rapidly adapt to UEM solutions for a smooth transition to remote work.

UEMs help a business to enforce complex password policies for maintaining data safety. Their capabilities include:

Separate personal and work data in BYOD.

• Prevent access to bad applications or websites.

• Lockdown devices to a single or a handful of applications.

• Dynamic device grouping and automatic deployment of restrictions and configurations based on the device’s status.

With the progress in technology, bad actors, too, will evolve and find new ways to challenge the industry. The quantity and magnitude of security threats can only increase and it’s imperative for businesses to survive the persistent threats. Having an awareness of the need to maintain cyber hygiene and being equipped to tackle the various challenges are the way forward.

Find out more at www.hexnode.com/unified-endpoint-management/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Managed security solutions for organisations of all sizes
Information Security News & Events
Cyber attackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Troye exposes the Entra ID backup blind spot
Information Security Infrastructure
If you trust Microsoft to protect your identity, think again. Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra?ID – formerly Azure AD – but it does not.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...
Check Point launches open, vendor-neutral MDR services
Information Security News & Events Products & Solutions
New Check Point MDR 360° and MXDR 360° offerings deliver 24/7 managed continuous threat monitoring protection across endpoints, cloud and network environments with built-in identity threat detection and 160+ integrations across hybrid, multi-vendor environments.

Read more...
Credential theft surges in South Africa
NEC XON Information Security
NEC XON issues a critical cybersecurity warning about the dual threat of massive credential theft and AI-powered cyberattacks sweeping across the region, with an increasing number of incidents and evolving threat tactics.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.