Miles IT “Cyber Security: The Ultimate Guide for Businesses” displayed as a digital guide on a tablet alongside a printed book, with cybersecurity, shield, and padlock graphics.

Cybersecurity is top of mind for businesses in 2022. Engaging in necessary discussions with your staff, vendors, and service providers isn’t tricky if you have a solid working vocabulary.

As with any industry, the cyber world has its jargon—a framework of terms that outline problems and describe solutions.

All successful cybersecurity attacks share a common goal—a financial jackpot of ill-gotten gains.

Attackers want money. It can be cash deposited into a Bitcoin wallet. It could also be theft of customer data or proprietary business information converted to currency at sinister auction sites on the deep or dark web.

There’s been exponential growth in the number and sophistication of tools, tactics, and strategies for today’s cyber attacks.

The two primary attack vectors in 2021 are ransomware and phishing.

Phishing attacks, aka Business Email Compromise, have been evolving over the years, as well-financed criminal organizations are taking a more dominant role. The majority of pre-2020 attacks cast a wide net, using automated systems to send messages to millions of harvested email addresses.

Today we see a shift from an automated process to targeted, highly creative phishing attack strategies that use social engineering and psychological manipulation to land bigger fish and a monster payday.

Spear-phishing targets a business’s department-level staff, often HR or Accounting. A typical payoff here is funds transfer fraud, tricking an employee into wiring money to a hijacked vendor bank account to the tune of millions.

Whale phishing points squarely at business owners and C-suite executives. These are longer-term scams that begin with deep research into an executive’s business and personal life.

Nothing in a CEO’s private world is sacred or off-limits: family, personal email accounts, social media profiles, pet names, religious practices, hobbies, doctors, home contractors, community interests, politics, golf handicap, charities, writing style—anything to glean enough information to impersonate an executive online successfully.

CEOs are very busy people and don’t want to spend extra time on complicated security practices. Without knowing, owners of small- to mid-market businesses can make significant cybersecurity mistakes. The good news is that these are preventable.

Ransomware is a form of targeted malware that downloads onto your system, quickly encrypting all files and any backups, rendering them unusable—scorched earth.

Ransomware is hugely lucrative because large corporations continue to pay exorbitant ransom demands, chalking it up as a “cost of doing business.”

The FBI says financial setbacks due to weak cybersecurity will reach $6 trillion by 2021.

Systemic ransomware impacts multiple organizations in a single blast attack and usually doesn’t rely on hands-on action by threat actors. It’s highly automated malware with names like NotPetya or WannaCry. These scattershot attacks are typically broad in scope and geography.

Targeted ransomware focuses on individual organizations or entire industries. These attacks often involve data exfiltration of classified, personal information that the attacker threatens to release into the wild unless a company pays up. Stolen data can be auctioned off to the highest bidder, even if the company pays the initial ransom.

An encryption ransomware attack happens to your business when a staff member clicks a bogus email link or visits a compromised website (ensure you have an SSL to help prevent this). In the blink of an eye, all files and data backups are encrypted and become unusable by you. Attackers demand a cash ransom to purchase a “decryption key” to restore the integrity of corrupted files and resume normal business operations.

Ransom demands vary, from a few hundred dollars to millions of dollars. Whatever the market will bear, payable in Bitcoin or other untraceable cryptocurrencies. Colonial Pipeline recently paid a roughly $5 million ransom to the DarkSide ransomware group.

If you don’t pay, the only other option would be to start from scratch and try to restore your entire technology infrastructure from off-site backups, assuming you have those. Even if you have viable cloud backups, it could take weeks or even months of business downtime to restore network servers and reimage all workstations.

People’s actions are inherently unpredictable.

All cyber attacks have a human component—a person’s unfortunate decision to click a suspect link or open a document from an unknown person or organization.

We can’t predict individual cyber attacks any more than we can know in advance the exact epicenter and magnitude of earthquakes.

But as with earthquakes, we know that cyber attacks are a reality and prepare for them as best we can.

A cybersecurity incident response playbook is a set of rules and actions for a planned systems recovery before a cyber attack cripples an organization. The first 24 – 48 hours is crunch time for any attack on your IT systems. Know what to do, when to do it, and who’s in charge of it.

Having these stages and assigned roles in place ahead of the attack can lessen the severity and improve the eventual outcome.

Most likely, you’ll be dealing with career criminals looking for an easy score. These large groups are professional, well organized, well funded, and well versed in cyber operational security (OpSec).

Ransomware attackers research how much your business can reasonably afford to pay and whether you have cybersecurity insurance coverage to defray the ransom cost.

If you decide to pay, you’ll receive a decryption key to rescue your files. Instead, you might choose to restore your information systems from backups. Depending on the size of your IT infrastructure, that could take days, weeks, or even months of lost productivity.

Ransomware as a Service (RaaS) and the abundance of exploit kits available on the dark web has introduced a new layer of disarray into an already chaotic situation. 2021’s cyber attack landscape is like the wild west, and standard “rules” no longer apply.

Even if your organization agrees to pay the ransom, newbie hackers with eyes on a big payoff can complicate the process in many ways. Some, fearing law enforcement, get cold feet and break contact completely.

These types often re-negotiate the ransom amount or demand payment in an obscure cryptocurrency—not the standard BitCoin. This back-and-forth can significantly increase lost productivity.

Paying the ransom doesn’t guarantee that your files will decrypt correctly. New for 2021, many criminal syndicates offer “helpful customer service” to help with decryption efforts.

Some companies choose not to pay for a decryption key if they know they can restore systems from backups quickly. Attackers employ double-extortion to increase the likelihood of getting paid.

They download sensitive information from the victim’s systems in advance of encrypting their files—intellectual property, customer information, financials, and the like.

The threat actor can now make an additional ransom demand to prevent broadcasting sensitive data to the public. More and more often, attackers are seeking payment before agreeing to show what data they exfiltrated.

Realistically, it’s almost impossible to 100% prevent a devastating cyber attack from happening—but there are best practices you can put in place to reduce your risk so that a data breach event in your organization wouldn’t be catastrophic.

We put together ten proactive steps you can take now to bulk up your security posture and protect against all forms of cyber attack.

According to the responsible party, criminal syndicate DarkSide, the attack was strictly money-motivated. Yet, the real-world blowback came in the form of millions of dry fuel tanks and a spike in energy costs across the board. That single episode demonstrates our society’s vulnerability to cyber terrorism.

Seemingly on the heels of that event, the White House responded with an executive order calling for “bold changes” and “significant investments” to a nation’s cybersecurity posture.

The May 12, 2021, Executive Order on Improving the Nation’s Cybersecurity is a long-overdue wakeup call and begins:

“The United States faces persistent and increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector, and ultimately the American people’s security and privacy.

The White House document continues on to define its role in the context of non-stop attacks on our business and technology infrastructure:

“The Federal Government must improve its efforts to identify, deter, protect against, detect, and respond to these actions and actors.”

This marks a significant turning point in US policy toward combating international cyber crime.

To end phishing and runaway ransomware attacks (in an ideal world), we, as an international society, would need to find a way to accomplish some or all of these ideals:

Until we make measurable progress toward achieving these ideals, each year will continue to bring record losses.
As for your business, you can take action today.

What do you plan on doing to improve your security posture this year?

Hopefully this guide has provided you with enough direction to begin implementing a robust cybersecurity plan and the confidence to promote security awareness within your company.

Scroll to Top