Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/31/2020
10:00 AM
Marc Wilczek
Marc Wilczek
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

How Much Downtime Can Your Company Handle?

Why every business needs cyber resilience and quick recovery times.

Cyber incidents in the past few years have captured the attention of business executives. The World Economic Forum's "Global Risks Report 2020" cites cyberattacks among today's top 10 business risks in terms of their likelihood of occurring and ability to inflict catastrophic damage. According to PwC's "Global CEO Survey," 53% of American CEOs are losing sleep over the potential for cyber threats to obliterate their company's prospects for growth.

Remember Hurricane Katrina, the brutal Category 5 hurricane that hit Florida and Louisiana in 2005? Causing a mindboggling $125 billion in damages, it was America's most destructive natural disaster ever. Still, the fabled insurer Lloyd's of London warned in 2017 that cyberattacks could wreak even worse damage.

Cybercrime will be a massive problem for businesses and governments over the next 10 years. Because companies and societies everywhere now rely on always-on IT networks, hiccups or stoppages can have wide-ranging negative effects — and cloud services are major targets.

Cloud Computing: A Double-Edged Sword
Corporate use of cloud computing has greatly expanded. Expenditures on it reached $273 billion in 2018 and are expected to reach $623 billion by 2025, according to industry reports.

But when petabytes of data are stored in the cloud, there is a twofold exposure to significant risk. If the local Internet service is attacked — say, overwhelmed by a distributed denial-of-service (DDoS) attack — no data will be processed. A DDoS attack in October 2019 took down Amazon Web Services (AWS) for roughly eight hours. Users couldn't connect because AWS misread their genuine queries as malicious. The Google Cloud Platform was hit by similar troubles at about the same time, but Google says they weren't due to a DDoS.

According to Link11's "2019 DDoS Report," the biggest attack we're aware of topped out at 724 Gbit/s in bandwidth. (Full disclosure: I am the COO of Link11.) This is significant because many large companies have a 10 Gbit/s or a 1 Gbit/s Internet connection, so a data tsunami of this size would exceed the size of the pipe by 70 to 700 times. This would stop the victim company's business in its tracks. And that means VoIP telephones would be useless for the entire duration of the attack.

What's even more ominous is the looming scenario of Industry 4.0, wherein production lines, warehouses, telematics services, smart grids, building automation (HVAC), etc., are all Internet-facing, meaning that a DDoS attack would be even more devastating. The longest DDoS attack Link11 defended during the second half of 2019 would have caused an outage for more than 100 hours, or five consecutive days.

The proportion of DDoS attacks that abused cloud servers grew from 31% in the second half of 2018 to 51% in the same period in 2019. Link11's research found that the number of attacks caused by cloud services more or less corresponded to the provider's market share: AWS, Microsoft Azure, and Google Cloud racked up more cases of corrupt clouds than smaller providers. In 2018, AWS accounts caused a 21-hour DDoS attack on the website of a California candidate for the US House of Representatives. One of the attacks disrupted a live political debate and generated roughly $30,000 in damages.

Complexity and Lack of Automation Create Security Challenges
FireMon's "2020 State of Hybrid Cloud Security Report" notes that many companies are losing the visibility required to safeguard their cloud systems. Eighteen percent of C-suite respondents see this as their biggest concern. Today, they need more vendors and enforcement points to maintain effective security.

Almost 60% of the respondents think their clouds have grown to the point that their ability to secure their networks in a timely way has been compromised. This percentage was about the same last year, meaning the industry has failed to make headway in this area. The number of security services and enforcement points needed to secure cloud networks is also growing: Just under 80% of respondents use two or more enforcement points. FireMon says that 59% said the same last year. Almost half of the respondents use two or more public cloud services, which further boosts complexity and lowers visibility.

The National Security Agency reports that cloud misconfigurations caused by human-errors are the top vulnerability for security incidents. This may come as no surprise if you consider that a troubling 65.4% of respondents still employ manual processes to manage their hybrid clouds. The Ponemon/IBM "2019 Cost of a Data Breach Report" finds that only 16% of companies use fully automated security solutions.

The potential financial consequences of this are huge. The average total cost of a data breach is 95% greater in companies that lack automated security.

New Regulations and Growing Costs
With revenue, profits, and reputation depending upon the availability and integrity of IT systems, the regulations that dictate network security are tightening up — far beyond GDPR,CCPA, and HIPAA.

The new Federal Financial Institutions Examination Council (FFIEC) guidelines state that if a cyberattack disrupts a company's operations, the firm must be back online within its "maximum tolerable downtime." The policy further stipulates that "whether driven by customer expectations or technological advancement, previously established [recovery time objectives (RTOs)] that were a few hours in duration may now require near real-time recovery. Therefore, it may be appropriate for management to reevaluate currently acceptable RTOs."

The message is clear: Time is of the essence. Malicious breaches are the most common, but inadvertent breaches stemming from human error and system glitches are still the root cause of nearly half (49%) of security incidents. The Ponemon/IBM study says that, respectively, these cause an average loss of $3.24 million and $3.5 million per incident. The cost of lost business averages $1.42 million.

Organizations in the middle of a large migration to the cloud at the time of an incident saw costs jump by $300,000, for an adjusted average cost of $4.22 million. The Ponemon/IBM report says that system complexity increased the cost of a breach by $290,000, for an average cost of $4.21 million.

The Final Word
Simply put, the faster a security incident can be dealt with, the lower its costs. Strict security automation and intelligent orchestration are key to containing damages. As companies implement cloud and digital transformation, they'll need security solutions that work seamlessly across multiple clouds. The RTOs of current solutions must be reviewed, as some may be unable to keep abreast of changing business demands. Two ways to offset the costs of a security incident are to create an incident response team and to extensively test the incident response plan.

Related Content

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "What Should I Do If Someone Is Impersonating My Company in a Phishing Campaign?"

Marc Wilczek is a columnist and recognized thought leader, geared toward helping organizations drive their digital agenda and achieve higher levels of innovation and productivity through technology. Over the past 20 years, he has held various senior leadership roles across ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/23/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Russian Military Officers Unmasked, Indicted for High-Profile Cyberattack Campaigns
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-24847
PUBLISHED: 2020-10-23
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticat...
CVE-2020-24848
PUBLISHED: 2020-10-23
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent access to the local system.
CVE-2020-5990
PUBLISHED: 2020-10-23
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which may lead to local privilege escalation, code execution, denial of service or information disclosure.
CVE-2020-25483
PUBLISHED: 2020-10-23
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
CVE-2020-5977
PUBLISHED: 2020-10-23
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.