Darktrace Predicts Changing Role for CISO

Darktrace Predicts Changing Role for CISO

Looking forward, Darktrace is offering its 2023 Predictions, including where we can expect to see changes in MFA where accessibility and usability continue to dominate the discussion; continued Hactivism from non-state actors where ‘know thy enemy, CISOs lean in on more proactive security and crypto-jackers will get more savvy. CISOs will turn to AI-driven methods to understand attack paths.

Attacker Tradecraft Centers on Identity and MFA
At the core of the vast majority of cyber incidents is the theft and abuse of legitimate credentials, including the recent Uber attack. In this case, Uber experienced a Multi-factor Authentication attack, and we saw that MFA can be defeated, and with Okta, that the MFA companies themselves become targets - potentially as a mechanism to reduce its effectiveness in other customer environments.

Once considered a ‘silver bullet' in the fight against credential stuffing, it has not taken attackers long to find and exploit weaknesses in MFA and they will continue to do so in 2023. MFA will remain critical to basic cyber hygiene, but it will cease to be seen as a stand-alone ‘set and forget' solution. Questions around accessibility and usability continue to dominate the MFA discussion and only to be amplified by increases in cloud and SaaS along with the dissolution of traditional on-prem networks.

Today and in the future, MFA should be viewed as one component of a wider zero-trust architecture, one where behavior-based analytics are central to understanding employee behavior and authenticating the actions taken using certain credentials.

Continued ‘hacktivism' from Non-state Actors Complicates Cyber Attribution and Security Strategies
The so-called ‘vigilante' approach to cyber geopolitics is on the rise. Recent attacks launched by groups such as Killnet, though limited in their operational impact, have not failed in their aim to dominate global headlines in light of the Russo-Ukraine conflict, mounting concerns that these citizen-led operations could become more destructive or that states could use these groups as a deniable proxy.

Yet claims that ‘Russia' launched these attacks can be misleading and add fuel to an already complicated political fire. Cyber attribution and deciphering the extent of state-level tasking is difficult, with blurred lines between state-aligned, state-involved and state-directed increasing the risk of escalation, collateral and misattribution.

In 2023, ‘knowing thy enemy' in cyber will be more complicated than ever before - but it is critical that organizations remain aware of the realities of cyber risk and cease to focus on the ‘boogie man' of the internet that features in sensationalist reporting. Persistent, widely available, lower-sophistication malware and run-of-the-mill phishing campaigns statistically remain a greater global risk to corporations than the newest, most devious exploit kit or ransomware typically associated with APT groups. As it gets harder to name the enemy, we should see organizations moving away from the headlines and towards ensuring operational stability based on a bespoke understanding of their unique risk profile.

Crypto-jacking Neglect Gets Dangerous
The hijacking of computer resources to mine cryptocurrencies is one of the fastest growing types of cyber-threats globally. These attacks are often overlooked as unthreatening ‘background noise', but the reality is that any crypto-mining infection can turn into ransomware, data exfiltration or even an entry point for a human-driven attack at the snap of a finger.

To achieve the scale of deployment that crypto-jackers are looking for, illegitimate network access may use something relatively low-cost - a pervasive software vulnerability or default, weak or otherwise compromised credentials. Straying from the basics may well allow a ransomware actor from following the same path.

In 2023, crypto-jackers will get more perceptive and we might start to see the detrimental effects of what is inevitable or negligible. Security leaders need to ask themselves: "How did this person get in?" How was this person able to shore up the easiest points of entry into the organization? Companies should not live with rogue software and hackers siphoning off their resources - particularly as rising energy prices will mean a greater financial loss is incurred because of illicit crypto mining.

Ransomware Rushes to the Cloud
Ransomware attacks are ever evolving, and as cloud adoption and reliance continue to surge, attackers will continue to follow the data. In 2023, we are likely to see an increase in cloud-enabled data exfiltration in ransomware scenarios in lieu of encryption.

Third-party supply chains offer those with criminal intent with more places to hide and targeting cloud providers instead of a single organization gives attackers more bang for their buck. Attackers may even get creative by threatening third-party cloud providers - a tactic which already impacted the education sector in early October when the Vice Society ransomware gang blackmailed Los Angeles Unified School District (LAUSD), the second largest school district in the United States, and published highly sensitive information, including bank details and psychological health reports of students on the darknet.

Recession requires CISOs to get Serious with the Board about Proactive Security
Cyber security is a boardroom issue, but with growing economic uncertainty, organizations are forced to make tough decisions as they plan 2023 budgets. Rising cyber-insurance premiums are one thing, but as more underwriters introduce exclusions for cyber-attacks attributed to nation-states, organizations will struggle to see the value in such high premiums. Both insurance and compliance have long been seen as ways of ticking the ‘protection' checkbox without achieving true operational assurance, and we need look no further than Colonial Pipeline to see that insurance cannot compensate for long-term business disruption and reputational damage.

In 2023, CISOs will move beyond just insurance and checkbox compliance to opt for more proactive cyber security measures in order to maximize ROI in the face of budget cuts, shifting investment into tools and capabilities that continuously improve their cyber resilience. With human-driven means of ethical hacking, pen-testing and red teaming remaining scarce and expensive as a resource, CISOs will turn to AI-driven methods to proactively understand attack paths, augment red team efforts, harden environments and reduce attack surface vulnerability. Maturity models and end-to-end solutions will also be critical, as well as frank communication between CISOs and the board about the efficacy of continuously testing defenses in the background.

Featured

  • Integration Imagination: The Future of Connected Operations

    Security teams that collaborate cross-functionally and apply imagination and creativity to envision and design their ideal integrated ecosystem will have the biggest upside to corporate security and operational benefits. Read Now

  • Smarter Access Starts with Flexibility

    Today’s workplaces are undergoing a rapid evolution, driven by hybrid work models, emerging smart technologies, and flexible work schedules. To keep pace with growing workplace demands, buildings are becoming more dynamic – capable of adapting to how people move, work, and interact in real-time. Read Now

  • Trends Keeping an Eye on Business Decisions

    Today, AI continues to transform the way data is used to make important business decisions. AI and the cloud together are redefining how video surveillance systems are being used to simulate human intelligence by combining data analysis, prediction, and process automation with minimal human intervention. Many organizations are upgrading their surveillance systems to reap the benefits of technologies like AI and cloud applications. Read Now

  • The Future is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reason. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. But as the number of cameras grows and resolutions push from HD to 4K and beyond, the cloud’s limits are becoming unavoidable. Bandwidth bottlenecks. Latency lags. Rising storage costs. These are not abstract concerns. Read Now

  • Right-Wing Activist Charlie Kirk Dies After Utah Valley University Shooting

    Charlie Kirk, a popular conservative activist and founder of Turning Point USA, died Wednesday after being shot during an on-campus event at Utah Valley University in Orem, Utah Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities