The Changing Nature of Cyber Threats: What CEOs Need to Know

Is nothing sacred? A network of websites used by hackers to anonymously share information has itself been hit by cyber attack.

GettyImages-514571236-compressorIs nothing sacred? A network of websites used by hackers to anonymously share information has itself been hit by cyber attack. According to reports by the Wall Street Journal and other sources, the attack disabled a large chunk of the so-called Dark Web, knocking thousands of websites offline. When cyber attackers are themselves the target of cyber attacks, you know nothing is safe.

In 2016, cybercrime cost the global economy over $450 billion, according to the Hiscox Cyber Readiness report 2017, a comprehensive study of how ready and prepared businesses are when it comes to cyber threats. Forty-four percent of all U.S. companies surveyed reported taking two days or more to discover a cyber security incident and more than half (54 percent) reported taking two days or more to return to normal business after a large breach.

The trouble is, the nature of cyber threats have changed both in kind and intensity. State actors from Russia and Eastern European countries have raised their game and increased their intensity. Far from being spotty-faced teenagers operating from their mother’s basement, almost three-quarters of American companies cite the evolving nature of cyber threats as a major security challenge for their businesses. Where large companies have ramped up their security measures, small businesses lose, on average, $41,000 per single cyber incident.

“The landscape is constantly evolving and the nature of threats is a moving target.

Gary Steele, CEO of Proofpoint, a Sunnyvale-based cybersecurity company, points to several trends and developments of concern to CEOs:

1. The rise of ransomware. This form of attack has been around for decades, but the incident of holding organizations hostage is rapidly growing. Sunny Valley Hospital in Los Angeles, for example, had its system down for weeks until it was forced to pay the ransom. This meant patient records were compromised and surgical operations had to be delayed.

2. Spoofing. $3 billion in bad actor losses result due to spoofing, for example, to the accounts payable or HR departments, according to the FBI. There is no malware involved, which makes this form more invidious.

3. Phishing attacks. Attackers target employees using innocent-looking queries to trick people into giving dubious sources sensitive information, or credentials to access company networks. Bad actors here include foreign state sources, not just the usual criminals.

It’s not just banks and financial institutions anymore. Hackers can go after small and mid-size firms either for intellectual property or ransom, precisely because the target organization’s systems are often more vulnerable.

Here are some measures that CEOs and boards need to take, per Steele:
1. Raise the level of one’s cybersecurity team. Having a strong team in place can make a significant difference in detecting threats and, more importantly, taking active measures to halt the threat. Seventy-two percent of large companies and 60 percent of small to midsized companies experienced at least one cyber-attack in the past year.

2. Reduce your vulnerability with Internet of Things. Hospitals are particularly at risk. Every single medical device is connected to the Internet. Not all devices are safeguarded. “You would be amazed at how many such devices use older, unpatched versions of Windows,” says Steele. “It’s shocking.” He adds, “There is no simple answer other than to ensure that one’s own system is secure and that of all your supply chain partners have secure systems.”

3. Employee training is a must. For three-quarters of U.S. companies, employee training has significantly reduced the number of cyber hacks and incidents, according to the Hiscox report. Seventy-one percent of U.S. companies reported conducting cybersecurity exercises such as phishing experiments to understand employee behavior and readiness for an attack.

“There is no silver bullet,” says Steele. “The landscape is constantly evolving and the nature of threats is a moving target.” To keep up, CEOs must ensure that their systems are constantly being tested and improved.


MORE LIKE THIS

  • Get the CEO Briefing

    Sign up today to get weekly access to the latest issues affecting CEOs in every industry
  • upcoming events

    Roundtable

    Strategic Planning Workshop

    1:00 - 5:00 pm

    Over 70% of Executives Surveyed Agree: Many Strategic Planning Efforts Lack Systematic Approach Tips for Enhancing Your Strategic Planning Process

    Executives expressed frustration with their current strategic planning process. Issues include:

    1. Lack of systematic approach (70%)
    2. Laundry lists without prioritization (68%)
    3. Decisions based on personalities rather than facts and information (65%)

     

    Steve Rutan and Denise Harrison have put together an afternoon workshop that will provide the tools you need to address these concerns.  They have worked with hundreds of executives to develop a systematic approach that will enable your team to make better decisions during strategic planning.  Steve and Denise will walk you through exercises for prioritizing your lists and steps that will reset and reinvigorate your process.  This will be a hands-on workshop that will enable you to think about your business as you use the tools that are being presented.  If you are ready for a Strategic Planning tune-up, select this workshop in your registration form.  The additional fee of $695 will be added to your total.

    To sign up, select this option in your registration form. Additional fee of $695 will be added to your total.

    New York, NY: ​​​Chief Executive's Corporate Citizenship Awards 2017

    Women in Leadership Seminar and Peer Discussion

    2:00 - 5:00 pm

    Female leaders face the same issues all leaders do, but they often face additional challenges too. In this peer session, we will facilitate a discussion of best practices and how to overcome common barriers to help women leaders be more effective within and outside their organizations. 

    Limited space available.

    To sign up, select this option in your registration form. Additional fee of $495 will be added to your total.

    Golf Outing

    10:30 - 5:00 pm
    General’s Retreat at Hermitage Golf Course
    Sponsored by UBS

    General’s Retreat, built in 1986 with architect Gary Roger Baird, has been voted the “Best Golf Course in Nashville” and is a “must play” when visiting the Nashville, Tennessee area. With the beautiful setting along the Cumberland River, golfers of all capabilities will thoroughly enjoy the golf, scenery and hospitality.

    The golf outing fee includes transportation to and from the hotel, greens/cart fees, use of practice facilities, and boxed lunch. The bus will leave the hotel at 10:30 am for a noon shotgun start and return to the hotel after the cocktail reception following the completion of the round.

    To sign up, select this option in your registration form. Additional fee of $295 will be added to your total.