{"id":635,"date":"2024-06-24T11:57:44","date_gmt":"2024-06-24T09:57:44","guid":{"rendered":"https:\/\/www.cloudtango.net\/blog\/?p=635"},"modified":"2024-06-24T11:57:44","modified_gmt":"2024-06-24T09:57:44","slug":"looking-back-at-2023-and-what-we-learned-in-cybersecurity","status":"publish","type":"post","link":"https:\/\/www.cloudtango.net\/blog\/2024\/06\/24\/looking-back-at-2023-and-what-we-learned-in-cybersecurity\/","title":{"rendered":"Looking Back at 2023 and What We Learned in Cybersecurity"},"content":{"rendered":"<p><span data-preserver-spaces=\"true\">Another year and era of tech draws to a close as we look ahead to changes, adaptions, and industry movements in the tech sector. Part of change involves looking at the past, and reviewing 2023 is a great way to prepare for trends and shifts.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">But much of 2023 also engaged with familiar territory. Cybersecurity problems ranging from breach events, critical infrastructure attacks, and ransomware schemes were all the rage over the year. We also observed continued growth of AI-adjacent markets, technologies, toolsets, and pop culture emphasis as advanced machine learning took center stage. Laws, mandates, and regulations regarding IT and cybersecurity have tightened with stronger reporting requirements.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Just as we examine trends for 2024, let\u2019s take a glance back at 2023 to see what we\u2019ve learned in Cybersecurity.<\/span><\/p>\n<h3><strong><span data-preserver-spaces=\"true\">The Ransomware Debacle<\/span><\/strong><\/h3>\n<p><span data-preserver-spaces=\"true\">Ransomware remains a persistent threat. Any network with caches of valuable data is at risk of falling victim to ransomware attacks. If the data is valuable to a person, then it\u2019s trying to compromise. By encrypting data, ransomware gangs and hackers force victims to capitulate and meet their demands. Normally, this is paying the \u201cransom\u201d through forms of\u00a0<a href=\"https:\/\/www.bytagig.com\/sanctions-incoming-for-cryptocurrency-to-discourage-cyber-attacks\/\" data-wpel-link=\"internal\">cryptocurrency<\/a>. Even if the victim does not pay, cybersecurity insurance programs routinely cover the damages and expenses.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">This problem continued throughout 2023. Ransomware targeted supply chains, critical infrastructure, and valuable IT data caches filled with personal information. Said information was used for extortion attacks and BEC (business email compromise). Because ransomware is difficult to track and remediate, it remains the go-to for threat actors.<\/span><\/p>\n<h3><strong><span data-preserver-spaces=\"true\">SEC\u2019s New Mandates and Compliance Requirements<\/span><\/strong><\/h3>\n<p><span data-preserver-spaces=\"true\">The United States Security and Exchange Commission (SEC) introduced new reporting requirements for applicable businesses and federal agencies in 2023. Primarily, this was to shift away from the \u201cguidelines and suggestions\u201d model to better enhance cybersecurity response. Before, companies (such as in the fintech sector) were not required to report breaches or adhere to specific requirements and cybersecurity rulesets. That, however, is changing.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">The summation of new requirements is that starting in 2024, publicly traded companies must report a data compromise or breach event within four days of discovery. Discovery and companies falling under these categories can vary, so it\u2019s up to businesses to know if they\u2019re responsible for new data reporting mandates.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Threat actors may even adapt and threaten companies with \u201cfailure to compromise\u201d reports to the SEC for businesses not up-to-date with the SEC\u2019s requirements. Regardless of the reasons, it was one of the key factors shaping 2023 cybersecurity policies. As 2024 arrives, we\u2019ll see that change even more, with relevant companies adhering to reporting requirements and (hopefully) strengthening their IT infrastructure and cybersecurity posture.<\/span><\/p>\n<h3><strong><span data-preserver-spaces=\"true\">Zero-Day Vulnerabilities and Exploits<\/span><\/strong><\/h3>\n<p><span data-preserver-spaces=\"true\">Zero-day exploits are another top challenge for professionals across the board. A zero-day exploit can spell disaster for an enterprise, as hackers take advantage of vulnerabilities. Where those vulnerabilities are found will vary, but are common with software, apps, and even server frameworks. New patches and system updates can introduce zero-day vulnerabilities. Or the inverse, where weaknesses remain in unpatched applications.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Zero-day vulnerabilities and exploits are especially dangerous as ample time has not passed enough to fix or patch them. It\u2019s also hard to detect or know if a company is vulnerable to zero-day exploits without careful monitoring of their infrastructure, or, without alerts from parties that are aware of exploits. And, not all exploits are discovered in time. Even when they are, patching takes time, and damages to IT infrastructure can occur within these unfortunately exposed periods.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">2023 demonstrated we must remain aware of all company-adjacent systems and remain vigilant of potential exploits.<\/span><\/p>\n<h4><strong>Geopolitical Events and Turmoil<\/strong><\/h4>\n<p><span data-preserver-spaces=\"true\">Lastly, whenever geopolitical events occur, hackers will take advantage. The often \u201cintense\u201d discussion and consequences of world happenings, be they disaster, war, economic, or political, provide fertile ground for attackers to spread misinformation. They also take advantage of the confusion surrounding these events. For example, when the Russian-Ukraine conflict started, ransomware actors took advantage by preying on misinformation, fear, and weakened infrastructure.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">These were only a handful of happenings over the 2023 period. But as always, it\u2019s important to remain aware of them and learn valuable lessons.<\/span><\/p>\n<p><a href=\"https:\/\/bytagig.com\/contact\/\" data-wpel-link=\"internal\"><span data-preserver-spaces=\"true\">For additional help and information regarding IT, contact Bytagig for additional information.<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Another year and era of tech draws to a close as we look ahead to changes, adaptions, and industry movements in the tech sector. Part of change involves looking at the past, and reviewing 2023 is a great way to prepare for trends and shifts. But much of 2023 also engaged with familiar territory. Cybersecurity[\u2026] <a class=\"read-more\" href=\"https:\/\/www.cloudtango.net\/blog\/2024\/06\/24\/looking-back-at-2023-and-what-we-learned-in-cybersecurity\/\">Read<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" enable-background=\"new 0 0 24 24\" height=\"16px\" viewBox=\"0 0 24 24\" width=\"16px\" fill=\"#091926\"><rect fill=\"none\" height=\"16\" width=\"16\"\/><path d=\"M14.29,5.71L14.29,5.71c-0.39,0.39-0.39,1.02,0,1.41L18.17,11H3c-0.55,0-1,0.45-1,1v0c0,0.55,0.45,1,1,1h15.18l-3.88,3.88 c-0.39,0.39-0.39,1.02,0,1.41l0,0c0.39,0.39,1.02,0.39,1.41,0l5.59-5.59c0.39-0.39,0.39-1.02,0-1.41L15.7,5.71 C15.32,5.32,14.68,5.32,14.29,5.71z\"\/><\/svg><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-635","post","type-post","status-publish","format-standard","hentry","category-cybersecurity"],"_links":{"self":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/comments?post=635"}],"version-history":[{"count":1,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/635\/revisions"}],"predecessor-version":[{"id":636,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/635\/revisions\/636"}],"wp:attachment":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/media?parent=635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/categories?post=635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/tags?post=635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}