Cyberattacks increased 38% in 2015, costing companies worldwide somewhere between $400 billion and $750 billion.
It’s a major problem and most companies have no idea how vulnerable they are, though cybercrime is starting to become more of a priority in corporate boardrooms, according to John Collins, principal security architect and threat intelligence analyst with Dell SecureWorks in Atlanta, GA.
Speaking today to the Baton Rouge Rotary Club, Collins said threats to a company’s cyber security can come from several sources: mergers and acquisitions with other companies, vendors and other third-party sources that have access to a company’s IT system, and, above all, employees.
“Employee access is the number one threat vector,” Collins said. “Bad guys are good at taking advantage of human weakness.”
Mobile devices like phones and tablets that employees use to access company systems like email also pose a serious threat.
“Mobile devices are the largest risk,” he said. “But 50% of mobile endpoints are not protected.”
Security professionals cannot keep up with the “bad guys,” Collins said, because technology is changing so fast, and also because there aren’t enough trained security experts in the field.
“Security professionals are limited and in demand,” he noted. “For every one qualified candidate there are 20 open security positions.”
Businesses and organizations must take several steps to protect themselves against threats from the $500 billion hacker industry, which comprises individual hackers, activist groups, organized crime and nation states. Those steps include knowing where your organization is vulnerable, raising employee awareness through training and testing, responding to a potential threat as early as possible, and having an early warning strategy.
“Your adversary only needs to be right once,” Collins said. “Companies must be error free all the time.”
—Stephanie Riegel
