Tackling cyber threats in the post-pandemic era

Issue 8 2021 Information Security

Cybercrime costs are expected to increase by 15% each year over the next five years, reaching US$ 10,5 trillion by 2025. Threats like phishing, malware and ransomware attacks disrupt businesses, crush economies and even destabilise governments.

Remember the ransomware attack on Colonial Pipeline halting operations for six days, fomenting a severe fuel crisis and price spikes on the east coast of America for a week? Attacks like these have targeted industries as diverse as IT, healthcare, education, finance and logistics. The pandemic marked a significant rise in attacks on the cyber landscape with the integration of IT and operational technologies resulting even in critical infrastructure industries being targeted.

Nobody is safe

Cyber-attacks have targeted big enterprises like JBS, infiltrated Florida’s water supply and has exploited vulnerabilities even in Microsoft’s Exchange Server. With large enterprises keeping a keen eye on cyber-attacks and setting up dedicated teams and allocating resources to ensure cyber safety, attackers have shifted their focus to small and medium-sized businesses.

This is alarming on multiple levels. The most notable being the frightening statistic that 60% of small companies go out of business within six months of cyber-attack. SMBs normally lack the resources for handling cybersecurity or the ability to provide dedicated IT support and increased attack vectors are being targeted at SMBs, often jeopardising the businesses. With the pandemic, the evolution of hybrid work as a norm and the increased adoption of Bring Your Own Device (BYOD), attack surfaces have increased significantly.

Maintaining cyber health

According to Verizon’s 2021 Data Breach Investigations Report (DBIR),22% of data breaches involve phishing. According to Terranova Security’s ‘Gone Phishing Tournament,’ phishing email links get clicked by 20% of employees and almost 67,5% of employees provide their credentials on phishing websites. And one in 10 people even clicks on phishing links on mobile phones. Users need to be vigilant in clicking random links since phishing might lead to malicious websites and can steal critical data and information.

The essential awareness on not to click random links exists among users. However, discerning the legitimacy of an email is easier said than done, there are no explicit hazard signs unless you’re specifically prepared for them.

With most, if not all, services adopting a cloud-based model, clicking on an array of links for varied purposes is nothing unusual at a workplace. As a result, mandating the employees not to click on any link may be counterproductive and leave room for confusion and requires a lot more nuance.

One technique enterprises can use is to block known malicious email domains altogether, or only allow emails from trusted sources. There’s also an argument for a degree of cyber safety education, such as always checking the ‘sent from’ address on an email to make sure it actually matches the person requesting you click on a link or provide specific information.

Equipping the workforce to identify when they have clicked on something undesirable and to enable them to report it to the IT team is equally essential. Unfortunately, only a small percentage of companies are capable of identifying an attack in its early stages.

Nordpass, on analysis of passwords used at Fortune 500 companies, discovered that the companies were using passwords that could be hacked in less than a second. Maintaining a strong password is an often-overlooked elementary strategy to ensure data safety. It should be mandatory to train employees on the necessity to establish and maintain secure passwords.

Corporates need to enforce password policies like multi-factor authentication, using longer passwords with complex characters and changing the passwords frequently. Password managers can help generate strong passwords and store complex passwords separately. Various password managers like Keeper Security, Last Pass and 1 Password are leveraged by enterprises.

Legacy systems that employ outdated hardware/software are often prone to cyber-attacks since such systems lack the latest patches against new vulnerabilities and can’t incorporate the latest practices for cyber security.

The 2017 WannaCry attack exploited Microsoft’s end-of-life (EOL) for Windows XP. Enterprises that used Windows XP did not install the patch that could fix a vulnerability called EternalBlue. Since Windows XP reached the end of life in 2014, the OS lacked technical and security updates. Microsoft’s Windows XP, released in 2001, is still running on many desktops and laptops worldwide. Employing an EOL Operating system can cause security issues, growing maintenance costs and compliance and legal hassles.

Understanding cybersecurity and the way forward

Gartner predicts that by the end of 2023, more than 50% of enterprises will replace older antivirus products with combined Endpoint Protection Platforms (EPP) and Endpoint Detection and Response Solutions (EDR). EDR can detect advanced threats and malware that can get past conventional security architecture.

With the pandemic accelerating remote work at unprecedented levels, conventional strategies like firewalls, VPNs that create a perimeter around the network are no longer sufficient to safeguard the enterprise. A Zero Trust model removes implicit trust and ensures that no user is trusted by default. The Zero Trust model leverages micro-segmentation and organisations can secure corporate data by enforcing granular policies by role-based access. A Zero-Touch Network Access (ZTNA) grants access to specific applications and services employing encryption preventing users from accessing other services.

Complete visibility into the corporate assets

Managing the enormous volume of endpoints spread across diverse geographic locations is a challenging task for businesses. Unified endpoint management solutions are used by enterprises to manage varied endpoints like PCs, smartphones and IoT devices from a centralised console.

With remote work and BYOD, UEM solutions have gained significant prominence in businesses. In a normal scenario, businesses would have had difficulties or a time lag in facilitating new approaches. But the pandemic forced businesses to look for and rapidly adapt to UEM solutions for a smooth transition to remote work.

UEMs help a business to enforce complex password policies for maintaining data safety. Their capabilities include:

Separate personal and work data in BYOD.

• Prevent access to bad applications or websites.

• Lockdown devices to a single or a handful of applications.

• Dynamic device grouping and automatic deployment of restrictions and configurations based on the device’s status.

With the progress in technology, bad actors, too, will evolve and find new ways to challenge the industry. The quantity and magnitude of security threats can only increase and it’s imperative for businesses to survive the persistent threats. Having an awareness of the need to maintain cyber hygiene and being equipped to tackle the various challenges are the way forward.

Find out more at www.hexnode.com/unified-endpoint-management/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The impact of AI on security
Technews Publishing Information Security AI & Data Analytics
Today’s threat actors have moved away from signature-based attacks that legacy antivirus software can detect, to ‘living-off-the-land’ using legitimate system tools to move laterally through networks. This is where AI has a critical role to play.

Read more...
Managed security solutions for organisations of all sizes
Information Security
Cyberattackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Multiple IoT devices targeted
Information Security Residential Estate (Industry)
Mirai remains one of the top threats to IoT in 2025 due to widespread exploitation of weak login credentials and unpatched vulnerabilities, enabling large-scale botnets for DDoS attacks, data theft and other malicious activities.

Read more...
Local-first data security is South Africa's new digital fortress
Infrastructure Information Security
With many global conversations taking place about data security and privacy, a distinct and powerful message is emerging from South Africa: the critical importance of a 'local first' approach to data security.

Read more...
Sophos launches advisory services to deliver proactive cybersecurity resilience
Information Security News & Events
Sophos has launched a suite of penetration testing and application security services, designed to identify gaps in organisations’ security programs, which is informed by Sophos X-Ops Threat Intelligence and delivered by world-class experts.

Read more...
Kaspersky highlights biometric and signature risks
Information Security News & Events
AI has elevated phishing into a highly personalised threat. Large language models enable attackers to craft convincing emails, messages and websites that mimic legitimate sources, eliminating grammatical errors that once exposed scams.

Read more...
Software security is a team sport
Information Security Infrastructure
Building and maintaining secure software is not a one-team effort; it requires the collective strength and collaboration of security, engineering, and operations teams.

Read more...
Stronger cloud protection
Kaspersky Information Security Products & Solutions
Kaspersky has announced the release of an enhanced version of its Kaspersky Cloud Workload Security, delivering advanced protection for hybrid and multi-cloud environments.

Read more...
AttackIQ enters South Africa with key appointment
Information Security News & Events
AttackIQ, a provider of continuous security validation and exposure management, has announced its entry into the South African market with the appointment of Luke Cifarelli as its country manager.

Read more...
Managed security solutions for organisations of all sizes
Information Security News & Events
Cyber attackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.