Why threat intelligence plays a vital role in modern cybersecurity strategies

Emad Fahmy, Systems Engineering Manager, Middle East, NETSCOUT, explains how threat intelligence helps enterprises defend against today’s sophisticated cyber-attacks.

Cyberattacks and data breaches continue to escalate, reaching record levels. In fact, Forbes reports that the number of data breaches in 2021 has already exceeded 2020. Forbes cites a study claiming that the 1,111 data breaches detected so far this year surpasses the total number of data compromises from all causes in 2020.

With cyberattacks increasing and breaches making headlines, IT security teams are faced with the reality that existing tools are simply no match for this growing threat. To make matters worse, as the risk rises, so does the cost of combatting the threats and the potential losses from compromised businesses.

According to a 2021 survey by PwC, cybersecurity is a growing concern for organisations, with approximately 43% of Middle East CEOs planning to increase investments in cybersecurity and data privacy by 10% or more over the next three years. Moreover, 41% of these leaders think that their organisation should be doing more to measure cybersecurity. The ever-evolving threat environment has made it increasingly necessary to be vigilant.

A significant shortcoming of many of today’s cybersecurity tools is that the typical data sets feeding them are reactive, not granular, and do not extend to the earliest indications of a potential attack. This makes it difficult to identify threats early in the attack lifecycle. As a result, security professionals are not armed with the information to prevent infections from spreading, identify compromised assets, or stop future attacks.

How threat intelligence helps
Companies that do business on the internet or use network connections in any shape or form are vulnerable to cyberattacks. According to the 1H 2021 NETSCOUT Threat Intelligence Report, there were nearly 5.4 million distributed denial-of-service (DDoS) attacks in the first half of 2021.

However, while the threat landscape is often discussed in terms of attack numbers, experts in threat intelligence tend to think in terms of people: the adversaries behind the attacks.

When it comes to combatting distributed denial-of-service (DDoS) and ransomware attacks, threat intelligence is vital. Threat intelligence is the study of the bad actors who perpetrate these attacks, along with the tactics and tools they use. This involves unveiling the bad actor’s attack methodologies and why they are targeting those victims. This knowledge is then turned into actionable insight that enterprises can access and comprehend. Empowered with this knowledge, enterprises can learn about their network’s vulnerabilities to actively defend against threats. That actionable insight is crucial for defending against DDoS attacks. There were more than 10 million DDoS attacks in 2020 alone, and that record-setting pace continued into 2021.

Defending against sophisticated attacks
One new form of attack that is recently on the rise is DDoS extortion. In these cases, the attacker launches a demonstration attack against the victim and then follows up with an extortion demand. This demand typically states that the attacker has a lot more DDoS capacity and will direct that capacity at the victim if the extortion payment isn’t made. Indeed, respondents to the 16th annual Worldwide Infrastructure Security Report (WISR) reported a 125% increase in such attacks.

Moreover, bad actors are using triple extortion tactics, combining data encryption, data exfiltration, and DDoS attacks to create a three-pronged attack that increases the likelihood of the victim complying with the ransom demand.

In today’s increasingly fraught threat landscape, organisations must be prepared to defend themselves. This requires having a plan in place, successfully executing that plan, and regularly evaluating the plan’s effectiveness to strengthen it against subsequent attacks. The good news is, preparation pays off.

Ultimately, the fundamental aspect of DDoS defense is knowing the network. When it comes down to defending an organisation, a lot of it will come down to knowing what their services look like and what they depend on and then using practical solutions to fine-tune the correct level of defense. Threat intelligence is essentially a way of testing defenses protection so that enterprises can enhance them.

 

 

Media contact

Rebecca Morpeth Spayne,
Editor, Security Portfolio

Tel: +44 (0) 1622 823 920
Email: [email protected]

Georgina Turner image

Georgina Turner

Sales Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Copyright: Security Buyer

AmiViz Partners with Titania

AmiViz announced a strategic distribution agreement with Titania. This collaboration underscores a shared commitment to enhancing…
Malik Alyousef, Co-founder & COO, Mozn

Mozn Unveils a New Generation of AI Fraud Prevention

FOCAL by Mozn strengthens its Fraud Prevention Suite with Device Fingerprinting, Fraud Analytics, and Fraud Management as a Service…
NetApp

NetApp Appoints Suhail Hasanain

NetApp is pleased to announce the appointment of Suhail Hasanain as the new Regional Director for the Middle East and Africa region…
Axis Communications Riyadh website

Axis Communications opens new office and experience centre in Saudi Arabia

Axis Communications has officially inaugurated its new office and Axis Experience Centre in Riyadh, Saudi Arabia.
John Maddison website

Fortinet launches Lacework FortiCNAPP to enhance cloud-native security

In an advancement in cybersecurity, Fortinet has announced Lacework FortiCNAPP, providing organisations with visibility and security.
GITEX Global 2024 website

GITEX GLOBAL 2024: AI revolution drives strategic tech innovation

GITEX GLOBAL 2024 concluded on Friday, showcasing artificial intelligence (AI) as a transformative force driving business and economic growth
Perimeter website

Securing Boundaries in the Middle East

Perimeter security has become an integral part of protecting sensitive infrastructure across the Middle East.
SentinalOne

SentinelOne and Lenovo Collaborate

SentinelOne and Lenovo today announced a multi-year collaboration to bring AI-powered endpoint security to millions of Lenovo…
Gunnebo

Gunnebo Safe Storage at City Walk, Dubai

Gunnebo Safe Storage solutions have been specified for Private Vaults for Safe Deposits in Dubai’s premier lifestyle destination, City Walk..
Gallagher

Gallagher Security expands footprint in the Middle East

Gallagher Security is strengthening its foothold in the Middle East with the appointment of three new staff members joining their…
Scroll to Top