埃森哲-2020年网络威胁报告(英文)-2020.12-89页_2mb
报告摘要
2020 Cyber Threatscape Report Summary
Core Content
The 2020 Cyber Threatscape Report by Accenture provides a comprehensive analysis of the evolving cybersecurity landscape, particularly in the context of the global impact of the COVID-19 pandemic. It highlights five key trends that have emerged, shaping the way cyber threats are being executed and detected.
Main Trends and Key Points
01. COVID-19 Accelerates the Need for Adaptive Security
- Overview: The pandemic has created new cybersecurity challenges, including increased phishing attempts and operational disruptions.
- Key Observations:
- Companies must plan for long-term cybersecurity challenges.
- Phishing campaigns have targeted governments and organizations, using the pandemic as a lure.
- Work-from-home (WFH) policies have shifted security focus to cloud and virtualized infrastructure.
- Misconfigurations in home networks and VPNs pose risks to data leakage and theft.
- Organizations should ensure employees are aware of information protection procedures and best practices for home network security.
- There is a need to review and secure VPN configurations to prevent DNS leaks and other vulnerabilities.
02. New, Sophisticated TTPs Target Business Continuity
- Overview: Cyber threat actors are using increasingly sophisticated techniques to target business continuity systems.
- Key Observations:
- Attackers are exploiting vulnerabilities in established platforms such as Microsoft Exchange and OWA.
- Use of zero-day exploits and internal command and control infrastructure is on the rise.
- Threat intelligence and threat hunting are essential to detect and respond to these advanced threats.
- Organizations should focus on identifying and tracking priority adversaries and implementing tailored threat intelligence strategies.
03. Masked or Noisy Cyberattacks Complicate Detection
- Overview: Cyber attackers are using off-the-shelf tools and living-off-the-land techniques to evade detection.
- Key Observations:
- Off-the-shelf tools are used to create deniability and ease of use.
- These tools are often combined with native system utilities to mask malicious activity.
- Organizations must understand and validate the detection of these tools in their environments.
- An intelligence-led security approach is critical to addressing these evolving threats.
04. Ransomware Feeds New Profitable, Scalable Business Models
- Overview: Ransomware has become a more profitable and scalable business model for cybercriminals.
- Key Observations:
- Ransomware groups like Maze are using "name and shame" tactics to pressure victims into paying.
- Average ransom payments have increased significantly, with some reaching over $178,000 in 2020.
- The shift to remote work has created new vulnerabilities that ransomware can exploit.
- Accenture expects these tactics to continue and evolve in the coming months and years.
05. Connectedness Has Consequences
- Overview: The increased connectivity of critical systems has introduced new risks.
- Key Observations:
- More unpatched and untested IoT devices are being used, creating accessible targets.
- Cloud and internet-connected devices are widespread, and security testing varies significantly between manufacturers.
- There has been an increase in reported OT vulnerabilities, with vendors responding with patches.
- The challenge now is to apply this knowledge across all relevant systems.
- Security leaders should focus on standardizing and sharing best practices for securing connected environments.
Key Information
- Adaptive Security Elements: Accenture recommends four elements of adaptive security: secure mindset, secure network access, secure work environments, and secure collaboration.
- Threat Intelligence: Continuous and tailored threat intelligence is essential for identifying and mitigating risks.
- Geopolitical Impact: The pandemic has created new opportunities for politically motivated cyber espionage and disruption.
- Surveillance Tools: The use of surveillance technology has increased, raising concerns about data privacy and security.
- DDoS Risks: Increased bandwidth usage due to remote work has made organizations more vulnerable to DDoS attacks.
Conclusion
The 2020 Cyber Threatscape Report underscores the need for organizations to adopt adaptive security strategies in response to the new and evolving threat landscape shaped by the pandemic. It emphasizes the importance of threat intelligence, secure remote work practices, and a multi-dimensional crisis management approach to build cybersecurity resilience.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载