{"id":93459,"date":"2014-01-04T19:19:44","date_gmt":"2014-01-04T17:19:44","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=93459"},"modified":"2014-01-04T19:21:03","modified_gmt":"2014-01-04T17:21:03","slug":"biggest-corporate-security-threats","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/93459-biggest-corporate-security-threats.html","title":{"rendered":"Biggest corporate security threats"},"content":{"rendered":"<p>Kaspersky Lab recently published a report which provides an overview of the biggest corporate security threats of 2013.<\/p>\n<p>According to the report, companies are increasingly falling victim to cyber-attacks, with 91% of the organisations polled suffering a cyber-attack at least once in the preceding 12-month period.<\/p>\n<p>9% of businesses were the victims of targeted attacks &#8211; carefully planned activity aimed at infecting the network infrastructure of a specific organisation.<\/p>\n<p>\u201cThe extensive use of digital devices in business has created ideal conditions for cyber-espionage and the deployment of malware capable of stealing corporate data,\u201d Kaspersky Lab said.<\/p>\n<p>\u201cThe potential is so great that malicious programmes may soon completely replace company insiders as the way of gathering information.\u201d<\/p>\n<p>Kaspersky Lab\u2019s main corporate findings of the year are:<\/p>\n<ul>\n<li>spyware-led attacks related to various governments were revealed;<\/li>\n<li>most cyber-criminal incidents were aimed at stealing information;<\/li>\n<li>attacks on contractors were identified, instead of reaching big organisations; and<\/li>\n<li>new actor on the APT stage appeared: cyber-mercenaries conducting cyber-espionage on demand.<\/li>\n<\/ul>\n<h3 class=\"my-4\">The parties concerned and the attackers\u2019 goals<\/h3>\n<p>2013 saw some major disclosures about spyware-led attacks that were related, directly or indirectly, to the activities of various governments\u2019 agencies.<\/p>\n<p>Other significant actors on the corporate cyber threat scene were businesses that turned to cyber-criminals to penetrate their competitors\u2019 networks.<\/p>\n<p>Outsourced cyber-criminal forces performed operations that were usually aimed at stealing information.<\/p>\n<p>Other attacks were based on sabotage \u2013 using malicious programmes to wipe data or block infrastructure operations. Some special Trojan programmes were capable of stealing money via online banking systems.<\/p>\n<p>Cyber-criminals could also compromise corporate sites and redirect visitors to malicious resources, damaging a company\u2019s reputation.<\/p>\n<p>Financial losses were caused by a DDoS attack, which can close down a company\u2019s public-facing web resources for several days.<\/p>\n<p>Clients start looking for a more reliable company, which results in long-term financial losses.<\/p>\n<h3 class=\"my-4\">The rise of the cyber-mercenaries<\/h3>\n<p>Over the past few years, Kaspersky Lab\u2019s experts have observed big and noisy APT gangs all over the world targeting large numbers of organisations from almost all sectors.<\/p>\n<p>They stayed in compromised networks for weeks and even months at a time, stealing every shred of information they could get.<\/p>\n<p>However, that approach stands less and less chance of going unnoticed for long, damaging their prospects of success.<\/p>\n<p>That\u2019s why a new emerging trend is witnessed: small hit-and-run gangs that attack with surgical precision. They appear to know very well what they need from the victims.<\/p>\n<p>Basically, these kind of attackers come, steal what they want and leave. Kaspersky Lab\u2019s experts have named them &#8220;cyber-mercenaries&#8221; \u2013 an organised group of people conducting cyber-espionage\/cyber-sabotage activities on demand, following the orders of anyone who pays them.<\/p>\n<p>Icefog, which was recently discovered, appears to be an example of this \u2013 an APT campaign in search of specifically required data.<\/p>\n<p>Manual analysis of the data stored in corporate networks was used with the help of remote-access technologies integrated into malware on infected workstations. Subsequently the cyber-criminals selected and copied the documents that they wanted.<\/p>\n<p>Kaspersky Lab\u2019s analysts expect this trend to grow in future, and more small groups of cyber-mercenaries will be available for hire to perform surgical hit-and-run operations.<\/p>\n<h3 class=\"my-4\">Consequences of government-related disclosures<\/h3>\n<p>The infamous disclosures of 2013 could potentially lead to a kind of de-globalisation and greater interest in creating national equivalents of global services.<\/p>\n<p>Those new national software products and services delivered by local manufacturers may not be of the same quality as those of the larger international companies.<\/p>\n<p>The investigation of cyber-attacks suggests that the smaller and less experienced the software developer is, the more vulnerabilities will be found in its code. As a result targeted attacks become easier and more effective.<\/p>\n<h3 class=\"my-4\">More on security<\/h3>\n<p><strong><a title=\"Worst passwords in the world revealed\" href=\"http:\/\/mybroadband.co.za\/news\/security\/93091-worst-passwords-in-the-world-revealed.html\">Worst passwords in the world revealed<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/93325-nsa-gchq-spying-on-video-gamers.html\">NSA, GCHQ spying on video gamers<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/93287-sanral-website-exposing-your-e-toll-bills-a-problem-lawyer.html\">Sanral website exposing your e-toll bills a problem: lawyer<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/93279-leading-tech-companies-call-for-us-surveillance-reform.html\">Leading tech companies call for US surveillance reform<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab provides an overview of the biggest corporate security threats of 2013<\/p>\n","protected":false},"author":23,"featured_media":84713,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[36,4848,5872,16182,463],"class_list":["post-93459","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-cyber-crime","tag-cyber-espionage","tag-kaspersky-labs","tag-security-2"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/93459"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=93459"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/93459\/revisions"}],"predecessor-version":[{"id":93933,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/93459\/revisions\/93933"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/84713"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=93459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=93459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=93459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}