SUPPLY CHAIN THE NEW WEAK LINK IN BUSINESS SECURITY AS RANSOMWARE ATTACKS INCREASE ACCORDING TO DIMENSION DATA

SUPPLY CHAIN THE NEW WEAK LINK IN BUSINESS SECURITY AS RANSOMWARE ATTACKS INCREASE ACCORDING TO DIMENSION DATA

Cyber-criminals are turning their attention to the supply chain as a new means to exploit business data

Singapore – 21 May 2018 –  2017 saw a worrying increase in ransomware and other cyberattacks targeting the supply chain, with the business and professional services sector receiving a significant increase of attacks, particularly in the EMEA region, which saw 20% of all attacks targeting this sector. This is according to Dimension Data that today published its Executive Guide to the NTT Security 2018 Global Threat Intelligence Report.

The businesses and professional services sector received 10% of global ransomware attacks, the third most targeted industry (up from sixth position in 2016), behind finance and technology. It also ranked third in the Americas (9%) and was the most vulnerable sector in EMEA, receiving 20% of all attacks.

As ransomware-related outsourced incident response engagements against financial institutions declined (a drop from 22% in 2016 to 5% last year), the business and professional services supply chain has clearly become a prime target for trade secrets and intellectual property theft, potentially exposing customer and business partner data.

Despite the drop in outsourced incident response engagements, the finance sector remains the number one target for cyber criminals who carry out regular reconnaissance to spot potential infrastructure and application vulnerabilities.

Mark Thomas, Dimension Data’s Group CTO for Cybersecurity said, “There are numerous moving parts to supply chains and outsourcing companies, which often run on disparate and out-dated network infrastructures, making them easy prey to cyber threat actors. Service providers and outsourcers are also a prime target, due to their trade secrets and intellectual property. Businesses need to wise-up to the very real threats against them, and ensure all aspects of their operations are robustly and securely protected.”

Technology was the second most cyber-attacked industry in 2017, with a 19% attack volume, with business and professional services moving to third place. Interestingly, attacks on the government sector last year dropped to 5% from 9% in 2016.

In 2017, there was a massive 350% rise in ransomware, representing 7% of all global malware attacks (up from 1% in 2016), and is set to continue due to the popularity of cyber adversary campaigns.

Other highlights in the NTT Security 2018 Global Threat Intelligence Report include:

  • The technology and finance sectors account for 70% of all attacks in the Americas. The US is a world leader in technology innovation while the finance sector collects and stores a vast amount of personal data which cyber criminals can monetise
  • Education was the most attacked sector in Australia (26%). With an open network model and collaborative environments that enable connectivity and research between students, campuses, colleges, and universities, this is a valuable target.
  • Attacks on the APAC manufacturing sector have dropped to a mere 7% (32% in 2016), because of the adoption of enhanced security governance and proactivity in raising cyber defenses.
  • Attacks against the finance sector decreased from 46% in 2016 to 26% in 2017, but it remained the most attacked sector in APAC. This was caused by service-specific attacks.
  • Increased attacks against education doubled: from 9% in 2016 to 18% in 2017.
  • China was the top attack source for manufacturing cyber-incidents, accounting for 67% of hostile activities targeting the sector in EMEA.

Click here to download Dimension Data’s Executive’s Guide to the NTT Security 2018 Global Threat Intelligence Report.

 

Dimension Data’s Executive’s Guide to the NTT Security 2018 Global Threat Intelligence report is compiled from data collected by NTT Security and other NTT operating companies including Dimension Data, from the networks of 10,000 clients across five continents, 3.5 trillion security logs, 6.2 billion attempted attacks, and global honeypots[1] and sandboxes[2] located in over 100 different countries.

 About Dimension Data

Dimension Data uses technology to help organisations achieve great things. As a member of the NTT Group, we accelerate our clients’ ambitions through digital infrastructure, hybrid cloud, digital workspaces, and cybersecurity. With a turnover of USD 7.4 billion in 2016, offices in 48 countries, and 30,000 employees, we deliver wherever our clients are, at every stage of their technology journey. We’re proud to be the Official Technology Partner of Amaury Sport Organisation, which owns the Tour de France, and the title partner of the cycling team, Team Dimension Data for Qhubeka. Visit us at http://www.dimensiondata.com

[1] honeynet and honeypot:  Honeypot: decoy systems set up to gather information about an attack or attacker and to potentially deflect that attack from a corporate environment. Honeynet: a network containing honeypot systems.

[2] sandbox:  software that executes suspicious code in a highly protected environment and examines its activities sandboxes