Building Your Foundational Knowledge

While levels of vulnerability to cyberattacks can vary by industry, no organization—regardless of sector or size—should consider itself safe. The increased prevalence of ransomware, which cost U.S. companies more than $20 billion in 2021, has pushed the severity of the threat landscape to new heights. A wide range of ransomware attacks occurred with victims ranging from large corporations to small businesses, major universities to secondary school districts, major hospitals to acute care facilities hospitals … and the list goes on.

Education was the top targeted industry for ransomware in 2021, experiencing a 75% increase in attacks from the previous year. Cyber breaches across the U.S. healthcare sector reached record highs as well, with 45 million individuals affected by ransomware attacks that exposed their personal information – a rate that has tripled over three years according to data from the U.S. Department of Health and Human Services. And in the U.S. financial industry, 90% of all institutions have experienced a ransomware attack over the past year. Similar trends are evident across energy and utilities, government entities, supply chains, and more.

Amid the acceleration of malicious attacks, the global rate of cybersecurity spending has never been higher. Gartner forecasts predict information security and risk management investments will total $172 billion in 2022, increasing from $155 billion in 2021 and $137 billion in 2020. As the threat of cyberattacks continues to rise, IT leaders across the public and private sectors face two key questions:

  • What amount of cyber spending will strengthen our security posture to defend against disruption, theft, and loss?
  • Which cyber investments will give us the agility to enhance our cyber operations team’s efficiency and effectiveness?

The challenge at hand is too complex for a firehose approach of simply throwing large sums of money at the problem and hoping it will go away. Effective cyber spending should always be about quality over quantity. The agility and rapidly changing signature of the tools behind today’s common cyberattacks enable threat actors to easily evade the plethora of legacy systems and perimeter-based controls on the market today, which weren’t designed to defend against the evolving tactics and techniques of attackers.

Taking A More Calculated Approach

It’s clear that a better understanding of the right (and wrong) areas to target with cyber spending is needed across the cybersecurity community. That understanding can only come from sharpening your cyber risk and vulnerability assessment. Analyze current risks, as well as any residual risks your organization is prepared to accept, to begin formulating a security investment roadmap. And assess the intersection of business goals, technical constraints, and availability of resources to identify any gaps or loopholes that are hampering your cybersecurity posture.

  • How well do your tools enable the security outcomes your organization needs and expects?
  • Do they align with the evolving threat landscape? If not, what do you need to keep pace in the future?

Then, take history into account by performing a root-cause analysis of past breaches that exposed certain vulnerabilities within your technology stack, human errors or insider threats. The following three questions can serve as optimal starting points:

  • Which vulnerabilities or organizational mistakes did the attackers capitalize on?
  • Why couldn’t the existing security measures detect the threat?
  • How could the attack have been prevented?

The answers stem from a lack of data-centric security. Data is at the core of most cyberattacks within today’s modern threat landscape – threat actors infiltrate networks to steal high-value data assets that are in turn leveraged for their personal gain.

For a ransomware attacker targeting a healthcare system, that asset could be patient electronic health records to hold for ransom. For a nation-state attacker targeting a federal government network, that asset could be the personal information of U.S. government officials to extort for sabotage. And for an insider threat actor targeting their own organization’s network, that asset could be product roadmap files to sell to an industry competitor. While their motives are different, the mission remains the same – stealing high-value data assets.

Shifting to Data-Centric Cyber Spending

In response, organizations should invest in security tools that actually address the root of the issue at hand. The adoption of data-centric cyberstorage solutions in place of traditional NAS and file shares is a perfect example. These solutions, deployable in any storage setting (on-premises, cloud, edge and hybrid environments), are the only scalable systems positioned to follow data-centric Zero Trust and effectively safeguard assets from the growing capabilities of attackers.

Unlike traditional NAS technologies, cyberstorage products go beyond just relying on identity access controls, backups, encryption keys, and other defense mechanisms that attackers already know how to beat. Instead, they leverage user behavior and entity analytics to automate the integration of active security controls with end-to-end data compliance monitoring, which generates real-time visibility of an organization’s entire data ecosystem to more effectively identify and respond to attacks.

From data protection and data integrity to data compliance, every stage of the data lifecycle is refined and accounted for – building an impenetrable layer of protection around the data asset itself rather than the larger network storing it. And by shaping their defenses around the asset and not the actor, enterprises in turn have the agility to combat whatever tactics the latter deploys. Embracing new data-centric security approaches is the only real way to gain meaningful ground in the fight against cybercrime.

Legacy systems and controls are the reason we’re stuck in this position in the first place. Why continue to blindly invest in them?

Featured

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West
  • New Report Says 1 in 5 SMBs Would Be Forced to Shutter After Successful Cyberattack

    Small and medium-sized businesses (SMBs) play a crucial role in the U.S. economy, making up 99.9% of all businesses and contributing to half of the nation's GDP. However, these vital economic growth drivers face an escalating threat—cyberattacks that could put them out of business. Read Now

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.