New Risks Exposed as IT Teams Respond to the Pandemic: Secureworks
Annual Secureworks Incident Response report highlights pandemic response trends and lessons
A new Incident Response (IR) threat report by Secureworks reveals that cybercriminals are targeting vulnerabilities created by the pandemic-driven worldwide transition to remote work. The report is based on hundreds of incidents the company’s IR team has responded to since the start of the pandemic.
While initial news reports predicted a sharp uptick in cyber threats after the pandemic took hold, Secureworks data on confirmed security incidents and genuine threats to customers show the threat level is largely unchanged. Instead, major changes in organisational and IT infrastructure to support remote work created new vulnerabilities for threat actors to exploit.
The sudden switch to remote work and increased use of cloud services and personal devices significantly expanded the attack surface for many organisations. Facing an urgent need for business continuity, many companies did not have time to put all the necessary protocols, processes and controls in place, making it difficult for security teams to respond to incidents.
Threat actors—including nation-states and financially-motivated cyber criminals—are exploiting these vulnerabilities with malware, phishing, and other social engineering tactics to take advantage of victims for their own gain. One in four attacks are now ransomware related—up from 1 in 10 in 2018—and new COVID-19 phishing attacks include stimulus check fraud.
Additionally, healthcare, pharmaceutical and government organisations and information related to vaccines and pandemic response are attack targets.
The Secureworks Incident Response report provides specific recommendations for how organisations can strengthen their defences by tuning their processes and tools for work-from-home environments.
Using expertise, cyber threat intelligence, and purpose-built technologies, the Secureworks incident response team helps organisations prepare for and respond to cyber incidents successfully. Secureworks Incident Commanders and teams work closely with in-house teams via emergency incident response services, threat hunting assessments, tabletop exercises, and a range of services to resolve incidents efficiently and effectively.
Barry Hensley, Chief Threat Intelligence Officer, Secureworks, said, “Against a continuing threat of enterprise-wide disruption from ransomware, business email compromise and nation-state intrusions, security teams have faced growing challenges including increasingly dispersed workforces, issues arising from the rapid implementation of remote working with insufficient consideration to security implications, and the inevitable reduced focus on security from businesses adjusting to a changing world.”