Home / Business and Politics / Cyber Attack Can Today Be Executed by Anyone Without Extensive Computer Knowledge

Cyber Attack Can Today Be Executed by Anyone Without Extensive Computer Knowledge

The European Union has declared October as Cyber Security Month (EU Cyber Security Month – ECSM), making it an opportunity to see if we are keeping pace with the developed Western world, not only in terms of attacks but also in protection against them. Indeed, anyone can become a victim of a cyber attack, which is why this year’s awareness-raising campaign for the European Cyber Security Month is aimed specifically at the general public.

The National CERT states that they keep statistics on cyber incidents according to types of incidents (in accordance with the National Taxonomy of Computer Security Incidents) and emphasize that particularly vulnerable groups include the elderly, citizens with low digital literacy, and micro, small, and medium enterprises that lack financial resources, knowledge, or human resources to deal with cyber security issues alongside their daily operations.

– They are most often attacked by attackers from outside Croatia, and the profiles, as well as their motives, can vary significantly. There is a basic division of attacker profiles into state-sponsored groups, cybercriminals, hacktivists, terrorist groups, internal threats, and actors for whom attacks represent some kind of challenge. Their motives vary and can be geopolitical, financial, ideological, or for personal satisfaction. Actors are increasingly turning to profit-driven activities as this secures funding for further actions – they explain at CERT.

However, perhaps an even more interesting point they make is that you can be cyber attacked not only by ‘masters’ of computers (as the legendary Nadrealists would say) but also by total beginners. This contrasts with the common belief among people, as many think (including the author of this text), if not everyone, that committing a cyber attack requires extensive knowledge and skill. Therefore, CERT warns about actors referred to as Script kiddies. These are beginners who use ready-made solutions, i.e., other people’s code, sometimes without understanding how they actually work.

Additionally, technical knowledge, they continue at CERT, is not necessary for the success of an attack, for example, for social engineering. This is an attack in which the victim is manipulated to achieve some benefit. Social engineering is precisely the main theme of this year’s campaign for the European Cyber Security Month, and if any readers want to learn more about it, they can find out everything during October on the CERT.hr portal and its social media.

Multiple Attacks from One Center

At the level of the European Union, data on incidents is collected, and significant effort is put into cooperation and information exchange between the CERTs of EU member states. Based on the collected information, recommendations are issued and forecasts are made regarding trends in the field of cyber security. The European Union Agency for Cybersecurity (ENISA) publishes the ‘ENISA Threat Landscape’ every year, which outlines the biggest threats and advice for protection against them. According to the ‘ENISA Threat Landscape 2022’ report, the biggest threats include: ransomware (which locks data on the computer), malware (malicious software that runs without the owner’s consent, causing damage), social engineering, DDoS (attacks that would cause internet unavailability, disinformation, and attacks on the supply chain).

Let’s focus a bit more on DDoS attacks. They target websites and servers by disrupting network services in an attempt to exhaust application resources. Attackers behind these attacks flood the website with random traffic, resulting in poor website functionality or complete network disconnection. These types of attacks are becoming increasingly common. DDoS attacks have a wide scope and target various activities and companies of all sizes around the world. Certain sectors, such as the gaming industry, e-commerce, and telecommunications, are targeted more frequently than others. DDoS attacks are one of the most common computer threats and potentially jeopardize your business, internet security, sales, and reputation.

And how dangerous cybercrime is, is not only indicated by the fact that attackers do not have to be physically close to commit it, but also that attacks and observed campaigns can occur in multiple countries simultaneously. This is best illustrated by the case of the WannaCry ransomware in 2017, which compromised over 200,000 computers in 150 countries.

Our So-So

How prepared are our companies, as well as organizations and institutions, for cyber attacks? Tomislav Novosel, a cyber security consultant at Duplico, says that our companies are still not aware of the seriousness of cyber attacks.

– Small and medium enterprises are particularly vulnerable here. Large companies have had to start implementing various security standards due to legal or contractual obligations, thereby strengthening their own cyber security. However, it has been noted that in many companies, security measures are implemented on the principle of ‘what we must’ or ‘to meet the formality.’ Unfortunately, this approach cannot build the necessary information security management systems that every company should have. Here, the NIS2 directive adopted at the EU level, as well as the new law on cyber security, plays a significant role. These laws should encourage our companies to take the necessity of cyber protection more seriously – says Novosel.

His colleague Filip Kiseljak, an information security expert at KING ICT, is somewhat more optimistic as he says that it can be said that awareness of the necessity of cyber security for business and overall functioning in a connected and digitized world is rising. This is contributed to by increasingly stringent legal and industry regulations, as well as the organizations’ own experiences or news about new attacks and damages that organizations have suffered.

– On average, regulated industries such as the financial sector and telecommunications are somewhat better prepared for cyber attacks than other industries. More and more organizations are realizing and accepting that cyber security is not a cost but a necessary investment for survival and functioning in the digital and connected world. To effectively manage risks and raise the level of cyber security, organizations are seeking reliable partners for the delivery of cyber security solutions and services – says Kiseljak.

Security Testing

However, generally speaking, this is insufficient, says Mate Matijašević, a cyber security analyst at Span, although he adds that it actually depends on the case.

– Integrating security into the fabric of the organization is a continuous and demanding process that requires significant financial investments. There are, of course, various open-source solutions that require a different type of investment, and this brings us to the problem of the lack of quality and skilled security personnel. What I would highlight as particularly problematic is the casual understanding of the very basics of security. I do not only mean the education of end users, especially in the domain of business process security, but also extremely important elementary processes such as managing digital assets. Of course, this process alone does not guarantee security, but it represents the cornerstone for other security controls because – you cannot protect what you cannot see – says Matijašević.

And CERT emphasizes that readiness varies from organization to organization and adds that CARNET’s department for the National CERT for CARNET member institutions regularly conducts security testing and issues security recommendations to make their systems and infrastructure as secure as possible.

– On our internet portal, warnings about current threats and campaigns targeting the citizens of the Republic of Croatia can be found. We also publish protection advice that every individual or company can apply to strengthen their resilience to cyber threats. Cyber security is a continuous process. Threats change from day to day, and only through regular awareness-raising campaigns, education, and user training can we ensure readiness for rapid response and increase resilience to cyber threats – they conclude at CERT.

Tagged: