Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

Analysis on cybersecurity and its main threats

ciberseguridadInternational. The evolving threat landscape ranked as the top driver affecting the information security organization over the next three to five years, according to a recent survey by Gartner, Inc.

"External risk is the most important thing for security and risk management leaders in 2020, yet COVID-19 has shown how quickly and how drastically such risks can change," said Jonathan Care, senior research director at Gartner. "Bad actors are always looking to take advantage of global events, such as the pandemic, to exploit new vulnerabilities and circumvent even the most advanced security controls."

Remote work
As organizations around the world moved to remote work driven by COVID-19, the number of remote desktop protocol (RDP) and virtual private network (VPN) services exposed increased, and widespread reliance on digital meeting solutions created new threat vectors. Security teams also had to develop new protocols for managing and patching remote terminals.

"Before the pandemic, most companies designed their appetite for risk around the assumption that remote work was the exception, rather than the norm," Mr. Care said. "When that scenario was changed, risks like always-on VPNs and bringing your own device, which were previously a lower priority for security leaders, suddenly became paramount. This forced security teams to quickly reassess their company's risk landscape and implement new solutions and policies accordingly."

- Publicidad -

Chaotic changes
Threat actors took advantage of the urgency and chaotic nature of changes in work environments to take advantage of new tactics. Gartner has observed an increase in reporting on coronavirus-related business email compromise (BEC) and phishing scams, including SMS phishing ("smishing") and credential theft attacks.

COVID-19 also led to an increase in nation-state activity from advanced persistent threat (APT) groups targeting healthcare and essential services. These actors are using scanning and exploitation techniques, as well as password dissemination that attempts to exploit unpatched vulnerabilities, to obtain massive personal information, intellectual property, and national intelligence.

Invest in agile systems
In response to the dynamic nature of the immediate threat landscape, Gartner recommends that organizations invest in security solutions that are agile enough to evolve along with them. "Many organizations waste time on legacy security technologies that have lost effectiveness or continue to unnecessarily tighten effective controls," Mr. Care said. "Instead of trying to anticipate and block all possible threats, invest in solutions with detection and response capabilities, which can help with unknown threats and improve response effectiveness when prevention fails."

Gartner predicts that by the end of 2023, more than 50% of enterprises will have replaced older antivirus products with combined endpoint protection (EPP) platforms and endpoint detection and response (EDR) solutions that complement prevention with detection and response capabilities. Extended detection and response (XDR) capabilities are also emerging to improve detection accuracy and security productivity.

Strategic evaluation
Security and risk leaders can use a continuous and adaptive strategic mindset of risk and trust assessment (CARTA) to evaluate vendor products and determine how they can build more adaptable defenses by applying the concepts of prediction, prevention, detection, and response.

Duván Chaverra Agudelo
Author: Duván Chaverra Agudelo
Jefe Editorial en Latin Press, Inc,.
Comunicador Social y Periodista con experiencia de más de 16 años en medios de comunicación. Apasionado por la tecnología y por esta industria. [email protected]

No thoughts on “Analysis on cybersecurity and its main threats”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Suscribase Gratis
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS

Webinar: NxWitness el VMS rápido fácil y ultra ligero

Webinar: Por qué elegir productos con certificaciones de calidad

Por: Eduardo Cortés Coronado, Representante Comercial - SECO-LARM USA INC La importancia de utilizar productos certificados por varias normas internacionales como UL , Ul294, CE , Rosh , Noms, hacen a tus instalciones mas seguras y confiables además de ser un herramienta más de venta que garantice nuestro trabajo, conociendo qué es lo que certifica cada norma para así dormir tranquilos sabiendo que van a durar muchos años con muy bajo mantenimiento. https://www.ventasdeseguridad.com/2...

Webinar: Anviz ONE - Solución integral para pymes

Por: Rogelio Stelzer, Gerente comercial LATAM - Anviz Presentación de la nueva plataforma Anviz ONE, en donde se integran todas nuestras soluciones de control de acceso y asistencia, video seguridad, cerraduras inteligentes y otros sensores. En Anviz ONE el usuario podrá personalizar las opciones según su necesidad, de forma sencilla y desde cualquier sitio que tenga internet. https://www.ventasdeseguridad.com/2...

Webinar: Aplicaciones del IoT y digitalización en la industria logística

Se presentarán los siguientes temas: • Aplicaciones del IoT y digitalización en la industria logística. • Claves para decidir el socio en telecomunicaciones. • La última milla. • Nuevas estrategias de logística y seguimiento de activos sostenibles https://www.ventasdeseguridad.com/2...

Sesión 5: Milestone, Plataforma Abierta que Potencializa sus Instalaciones Manteniéndolas Protegidas

Genaro Sanchez, Channel Business Manager - MILESTONE https://www.ventasdeseguridad.com/2...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter