Home / Finance / Threats are rising, while investments in information security have fallen. What to expect by 2030?

Threats are rising, while investments in information security have fallen. What to expect by 2030?

If you ask economists in which direction certain sectors will move in the future and where the most investments will be made, cybersecurity is usually among the top three, alongside investments in technological development. In Croatia, the National CERT Department has been protecting the Croatian cyber space for 15 years. This department is part of the Croatian academic and research network CARNET, which deals with the processing of cybersecurity incidents, raising awareness, and educating Croatian citizens about cybersecurity.

During 2022, CERT processed a total of 1,296 cybersecurity incidents, which is a seven percent increase compared to 2021. At the top are phishing and phishing URLs as forms of fraud, followed by scams.

Everything starts with identity theft

As much as 42.6 percent of all processed incidents are cases of phishing (online identity theft). A significant change, they say at CERT, relates to the increase in the number of incidents classified as scams, which in 2022, due to the increased number of citizen reports of that type of incident, came in second place.

– As the biggest cyber threats to companies and individuals, we would certainly mention phishing and ransomware. Phishing because it is the most common attack vector, meaning everything starts with phishing. Citizens are threatened daily by increasingly sophisticated phishing campaigns created to steal personal and banking data. In addition to phishing messages, there are phishing URLs that imitate legitimate systems and fake online stores of well-known fashion brands. We would mention ransomware as the next significant threat because it can cause downtime or even business interruption due to data loss, and the victims are not only companies but can also be individuals – they explain at CERT.

In January 2023, the National CERT processed a total of 139 incidents, and it can be concluded that since the beginning of the year, the number of threats of business fraud types – CEO fraud and BEC (business email compromise), frauds targeting bank users, phishing frauds using QR codes, critical vulnerabilities in VMware ESXi hypervisors, frauds where malicious attachments are delivered via email with the aim of stealing access data for Microsoft systems, and frauds imitating the e-Citizens system has increased.

Victim profile

The most common targets in the economy are, as confirmed by CERT, still banks and their customers, followed by energy facilities, healthcare institutions, as well as small and medium-sized enterprises.

– Banks and energy facilities have the highest level of protection, but due to potentially high rewards, they are constantly targets of cybercriminals. Small and medium-sized enterprises, which often do not think they could become victims of a cyber attack, are particularly vulnerable. Ransomware attacks that demand payment to potentially regain access to their data, in addition to reputational damage, can cause downtime or even business interruption. Attackers monitor events and adapt their actions to current topics. Thus, in Croatia, we had examples of attacks targeting mobile banking users, using the theme of transitioning to the euro for the attack – they emphasize at CERT.

Despite the growing awareness among citizens that cyber attacks are criminal offenses that need to be reported, the Ministry of the Interior states that the number of unreported such incidents remains quite high. However, it is increasing compared to previous periods

The Ministry of the Interior added that cyber incidents often appear in the form of campaigns; during such times, a very large number of incidents with common characteristics is recorded in a short period. Targeted attacks on a very specific target (e.g., a specific company) are rarer, but these attacks are usually highly sophisticated.

Given the trends of increasing numbers of attacks and their growing sophistication, it is surprising that companies’ investments in their own cybersecurity are declining. CERT presented data from the European Union Agency for Cybersecurity (ENISA) report, ‘NIS Investments 2022’, published at the end of 2022, stating that the share of the total IT budget of companies for information security is 6.7 percent, which is one percent less compared to 2021.

– Large enterprises in the EU allocate an average of 120,000 euros for cybersecurity per year, while small and medium-sized enterprises allocate an average of 5,500 euros. The banking sector invests the most in cybersecurity, which is not surprising considering that the average damage from a cybersecurity incident in that sector amounts to 300,000 euros, along with reputational damage – they add at CERT.

Criminal offenses

Although investments in cybersecurity are lower compared to 2021, experts say that total investments in cybersecurity have significantly increased since 2016, when the NIS directive was adopted, which set standards and requirements for cybersecurity in the EU. We asked CERT whether the profile of hackers involved in cybercrime is changing and in which direction, to which we received the answer that it is not entirely correct to view hackers exclusively in a negative context.

– One definition of a hacker is that it is a person who enjoys an intellectual challenge in which the limitations of a program or system are creatively circumvented, not necessarily a computer one – they explain at CERT, vividly adding a sci-fi profiling.

Thus, today the cyber space is guarded on one side by cybersecurity experts, while on the other, the darker side is attacked by so-called actors and/or hackers. The reasons, motivations, and goals of cyber attacks vary, but some of the most common are financial gain, confidential and personal information, curiosity, politics, or proving oneself.

Perpetrators who practice unauthorized access to computer systems commit criminal offenses as they are described and defined in Chapter XXV of the Criminal Code. The Ministry of the Interior states that, despite the growing awareness among citizens that cyber attacks are criminal offenses that need to be reported, the number of unreported cyber incidents remains quite high, although it is increasing compared to previous periods.

– Citizens and companies most often do not report such events to the police if they can rectify the damage themselves because they possess a copy of the data (backup) and if they do not lose data that is essential for business, they see no reason to file a criminal complaint. However, it is advisable for the affected party to report the event due to possible secondary consequences. The perpetrator can use the data obtained during the intrusion into someone else’s computer system (banking data, non-public personal and business data, passwords, discovered vulnerabilities of the computer system…) to commit other criminal offenses – they emphasize at the Ministry of the Interior.

Necessary hygiene

The most desirable targets are still larger companies, but they also invest the most in protection. CERT states that business entities must recognize cyber threats as a real danger and include them in their risk assessment of their business. They should understand them as an integral part of the process and upgrade the systems they already have.

‘Phishing’ and ‘ransomware’ are currently the biggest cyber threats to companies and citizens. This year, there has also been an increase in the number of so-called business frauds

Citizens should adhere to the rules of ‘cyber hygiene’, such as using a unique and strong password for each service, separating private from business devices, regularly updating systems, downloading content from secure sources, creating backups of their data, and above all, learning to recognize cyber threats in time and taking care of their personal data and digital footprint. Which, to be honest, few citizens do.

What we can expect in the future, CERT warns, is the emergence of new forms of fraud that we have not encountered before. As an example, they cite the increasing ingenuity of fraudsters in that instead of a link in an email, they use a QR code that leads to a malicious website.

– In this way, the attacker creates an illusion of legitimacy and security and further hides the address of the site they want to direct you to. Adding to this is the fact that the QR code needs to be scanned with a mobile phone, where it is harder to spot the fraud and the address of the site due to the smaller screen, significantly increasing the chance of fraud. With the development of AI, we can expect grammatically correct phishing emails, and how else they will be used and what types of attacks will be created remains to be seen – they conclude at CERT.

Top 10 biggest cyber threats we can expect by 2030:

  1. Supply chain compromise due to software dependencies
  2. Advanced disinformation campaigns
  3. Increase in authoritarian digital surveillance/loss of privacy
  4. Human error and exploitation of legacy and outdated systems
  5. Targeted attacks enhanced by smart device data
  6. Lack of analysis and control of space infrastructure and objects
  7. Increase in advanced hybrid threats
  8. Lack of skills
  9. Cross-border ICT service providers as critical points
  10. Abuse of artificial intelligence

Source: Report by the European Union Agency for Cybersecurity (ENISA)

Tagged: