Mike Puglia, General Manager, Security Suite, (MP) and Dave Baggett, Senior Vice President, Security Suite, Kaseya (DB) discuss the findings from the latest trend report
Mike, Kaseya’s latest reports highlight both progress and persistent gaps across SMB cybersecurity. From your perspective, what surprised you most about the findings this year?
MP: What consistently jumps off the page is that gap between companies that say they have experienced a cyber event and the low adoption of cybersecurity tools, frameworks and response capability. For every type of threat, organisations make a trade off to invest and address the threat or accept the risk. Clearly, too many are simply accepting the risk and the data shows the fallout from that approach.
Dave, as someone on the front line of phishing defence, how do these findings compare with what you’re seeing across INKY’s customer base?
DB: It’s quite consistent. In particular, phishing is still a preferred method for attackers to install malware/ransomware and steal credentials (via fake login pages linked from emails). It’s also very clear that no company is safe: there is no company too small for attackers to go after; we see evidence of that in spear phishing targeting even our smallest end customers. Targeting seems to be fully automated, e.g., via LinkedIn scraping, so it works against victims of any size.
Only 40% of organisations have a regularly tested incident response plan. Why do you think so many businesses still struggle with the basics of preparedness, despite understanding the risks?
MP: Unfortunately, this is a common theme of “it won’t happen to us” and it can seem overwhelming. I would argue that companies should implement an incident response plan before they implement any technology. It does not need to be complicated but it should at least identify the contacts who are responsible for which systems, the relationships between systems, and, at a minimum who to contact (external incident response company, legal, regulators, etc…). The panic and chaos that can follow an incident inevitably leads to a longer time to recover and additional damage.
Both reports point to significant downtime costs, with over a third of companies losing a full day or more after a breach. Mike, how can MSPs better quantify and communicate this impact to clients to drive stronger investment?
MP: Downtime and the direct costs can seem irrelevant to SMB executives. A day of downtime, while challenging, does not reach the threshold of being a critical business risk. What is missed is that a day of downtime due to a breach is equivalent to losing a month of business – if your company lost a month of business what would be the impact? The indirect impact of that breach is huge. Even though operations were restored in a day, the other factors such as reputation loss, legal fees for notifications, regulatory entanglements, insurance impact and opportunity costs of your staff being tied up with the fallout for at least a month must be taken into consideration.
Phishing remains the most damaging attack vector, affecting more than half of all businesses. Dave, how has phishing evolved in sophistication over the past year, and where are defences still falling short?
DB: What we see is constant innovation from attackers. We end-user reported phish to learn about new phishing tactics and the level of creativity is pretty astonishing. Email is built on multiple very complicated standards (MIME, HTML+CSS, Unicode) and we see over and over that the bad guys can find ways to exploit obscure corners of these standards to slip stuff through. In some cases, a new tactic can allow the attacker to reliably transit email security systems that aren’t hardened against the new method, so it’s a constant cat and mouse game.
An example is QR codes. By now most people know that a couple years ago attackers started encoding their bad URLs as QR code images; this meant that email security vendors had to add code to their pipelines to find and decode QR code imagery in email bodies and attachments.
But that’s not the fun part. The fun part is that this year, we started seeing QR codes constructed from Unicode box drawing characters. These are like the old school symbols in the original IBM PC character set that applications used to make all-text UI elements. Using these little shapes, attackers are crafting QR codes that your phone can scan just fine – even though they are nothing but Unicode text. So there is no image in the body of the mail; just these funny characters. This in turn means it’s no longer sufficient to just look for PNG or GIF files. So any email protection system that fails to render the mail in a headless browser or similar is just going to reliably miss these kinds of QR codes and let phish through. That’s just one example of a constant stream of clever ideas from bad actors…
Read the full interview here
