Why Has Industry Become an Easy Target for Hackers?

Cybercriminals are seeking leverage. Many companies choose to pay the ransomware ransom. After all, it looks cheaper than keeping operations at a standstill

Moreover, which sector would be the first target of hacker attacks? The most common reasoning points to banks or credit unions. After all, their business traditionally involves money. However, as we showed in the last article, industry took the lead in attack volume. That is according to the IBM report. Since then, manufacturing has stayed on top of the list, pressured above all by ransomware.

In practice, the “IBM Security X-Force Threat Intelligence Index” maps attack trends and patterns every year. The organization observes and analyzes them through its own data. In the 2022 edition, Latin America recorded 4% growth in cyberattacks compared to the previous year. Moreover, Brazil appears alongside Mexico and Peru among the region’s main targets.

Therefore, the question remains: could we explain why industry became hackers’ number one target? According to IBM’s own assessment, manufacturers sit at the base of supply chains. Therefore, they became the prime target of criminals.

The logic is simple. Paying the ransom may look cheaper than keeping operations halted for a long time. In addition, financial services achieved concrete results in the battle against cyberattacks. As a result, part of the malicious activity migrated toward less mature sectors.

“Cybercriminals usually chase the money. Now, with ransomware, they are chasing leverage,” said Charles Henderson, Head of IBM X-Force. “Businesses need to recognize that vulnerabilities are holding them in a deadlock. Ransomware actors are using that to their advantage,” he adds.

Industry plays a critical role

In short, criminals found a leverage point in the critical role manufacturing plays. After all, an idle production line pushes the victim to pay quickly. At bottom, this is data hijacking. Hence the name “ransomware,” in reference to the English word “ransom.”

Likewise, the model behind these attacks has changed a lot. Currently, ransomware as a service (RaaS) prevails: one group builds the malware and affiliates run the intrusion. Moreover, double extortion became the rule. Data is encrypted and also stolen, with a threat of publication. Therefore, restoring the backup no longer closes the incident.

According to threat intelligence reports, REvil was one of the most observed groups in Brazil in 2021.  The FBI held it responsible for the attack on JBS, the world’s largest meat supplier. That episode threatened the global food supply chain. However, the group vanished soon afterwards, as usually happens. Meanwhile, new brands emerge with the same code and the same people.

The path indicated by the experts

As a result, the path for industry is to follow what the financial sector adopted. After all, that sector left the top of the ranking. High security standards, therefore, do produce concrete results. In addition, hybrid environments and the cloud changed how data is managed and viewed.

Meanwhile, it is practically impossible to operate with the conviction that all vulnerabilities have been fixed. For this reason, you need immutable backups, tested for restore on a regular basis. In addition, a protection strategy for the entire business matters. Furthermore, a close look at internal infrastructure makes a difference. After all, exposed and unpatched systems remain among the most used entry doors.

Have you ever heard of the Green Cloud? Learn more about this concept on the blog.

The changes brought by hybrid work

In short, hybrid work stopped being an exception and became the norm in industry. The shift started with the pandemic, in 2020, yet it consolidated well after it. As a result, the corporate network now includes homes, phones, and cloud services. Moreover, the traditional perimeter lost practical meaning.

After all, the more distributed the operation, the longer it tends to take to contain an incident. That raises response costs and widens the damage. Therefore, identity became the new perimeter. In other words, whoever controls access controls the risk. Can this problem be reduced?

Yes, provided that security follows the real working model. In practice, that means conditional access, network segmentation, and visibility over device and session. Moreover, it pays to treat suppliers and integrators as part of the scope. After all, many industrial incidents come in through the supply chain.

Furthermore, the challenge lies in using data intelligence and AI to protect the company. Among the measures most cited by specialists are:

– Behavior-based detection – Machine learning models spot deviations in accounts, devices, and traffic. In this way, they reveal the attacker before encryption starts.

– Defenses against model deception – Attackers also study how to fool predictive algorithms. Therefore, it is wise to validate inputs and review models frequently.

In practice, these techniques are still evolving. Even so, companies should start studying them to find ways to prevent cyberattacks.

Recommendations against ransomware

So, what would be the good practices to increase protection? The first step is to have a ransomware response plan, designed strategically. As a result, you sharply reduce the time and money spent on the response. This strategy should include:

– Create an immediate containment plan. In addition, define how to inform authorities, regulators, customers, suppliers, and partners. It pays to rehearse the scenario before it happens.

– Structure immutable backups, isolated from the network and tested for restore. After all, a backup never restored is not yet a backup.

– Despite the investments, there is no guarantee that the attack will not occur. Therefore, calculate how much your company loses per day of downtime.

Do not forget the cloud: protecting this information requires additional tools, as well as team expertise.

– Deploy phishing-resistant MFA, with FIDO2 keys or passkeys, at every access point. Moreover, revoke stale sessions on a regular basis.

– Educate employees on current tactics. Today, phishing uses generative AI and arrives free of obvious mistakes. In addition, approval scams already rely on voice and video deepfakes.

– Keep an active security team focused on identifying vulnerabilities.

Likewise, do you know what digital resilience is? Download our e-book on the subject. (Coming soon)