Weekends and holidays: the days of hackers

• Η Kaseya, η Colonial και η JBS είναι μόνο μερικά παραδείγματα εταιρειών που έχουν πέσει θύματα κυβερνοεπίθεσης κατά τη διάρκεια ενός long weekend.

• And who does not like weekends and holidays? Cybercriminals are no exception, but they actually prefer to "work" during this time.

hacker

Everyone loves a long weekend and the holidays, but such dates can also be recorded in the calendars of cyber criminals. Once a cyber attack gains access to a corporate network during the holidays, it will have more time to spread, as offices are empty, making it easier for perpetrators to go unnoticed.

And now that we have reached this point, Check Point Software Technologies Ltd. , a cyber security provider, has issued a stern warning about the dangers behind not paying attention to your office's cyber security during the holiday season.

The trend of attacks on weekends and holidays is not something new. The FBI and Cyber ​​Security and Infrastructure Security (CISA) have already warned of the dangers following the large-scale attacks in the United States this year.

On July 4th, Independence Day, Kaseya, an IT management software company for msps, suffered a massive attack that affected 1.000 , with victims found in at least 17 countries.

The catastrophic cyber attack on the Colonial Pipeline - which supplies about 45% of the fuel throughout the East Coast of the United States - took place on Mother's Day weekend. As a result of this ransomware attack, it was forced to suspend its activities to deal with the threat.

On the Friday before Memorial Day weekend, giant JBS was forced to pay the equivalent of $ 11 million in Bitcoins as ransom to repel a cyber attack.

During a vacation period or a weekend, companies often operate with a core team, consisting of a small number of staff on alert for any type of incident. This facilitates the operation of criminals in cyberspace in various ways.

On the one hand, it allows the full development of a ransomware before anyone notices it and on the other hand causes more panic during the response operations, especially if the victim's IT teams are not available to respond. This, in turn, could increase the chances of a ransom claim being paid.

"Long weekends create the perfect conditions for threatening factors to cause maximum damage. You have to take into account the fact that, at the moment, everything is "paralyzed", so once criminals gain access to the network, there is much more time to expand the attack and reach a large number of computers and their data. This is one of the reasons why it is necessary to have a good cyber security prevention strategy and not to wait until the damage is done before you face the problem ", explains Vassilis Nikolopoulos, head of the Security Engineering team of Check Point Software Technologies in Greece.

Tips for protecting a company from cyber attacks

• Prevention strategy: In this day and age, it is important to have a precautionary cyber security strategy to prevent data theft and cyber security issues. In contrast to a response strategy, these methods aim to monitor attack markers (IoAs) and deal with all processes, technology, systems, and people, with an emphasis on preparing for an attack without waiting for it to happen.

• Zero trust strategy: according to Check Point Software's Threat Intelligence Report, 98% of malicious files in Greece were sent via email. This is why, across the industry, professionals they operate in a zero-trust security mindset: no device, user, workflow, or system should be trusted by default, regardless of where it operates, whether inside or outside the security perimeter. Applying these principles allows for a “Denial by Default” security posture where systems are made more inaccessible and isolated until a level of trust is established that will bring the highest level of protection to a system.

• Mobile device protection: data mobility is one of the main ones that should be considered when establishing a cyber security strategy. In today's paradigm, in which hybrid working has been adopted in most companies, there is a multi-device situation with many lacking adequate security measures. These businesses become the focus of many malicious campaigns by cybercriminals and therefore it is important to equip all devices with protective measures against any cyber attack.

• Cyber ​​training: very often one of the main entry points for a cyberattack is an employee's email or device, which is why this is one of the weakest links in any company: the lack of training for its members. It is of the utmost importance that company members are trained so that they are able to detect and avoid potential attacks. A social engineering message that encourages the user to do on a malicious link is enough. Education is often considered one of the most important defenses that can be developed.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
hackers, hackers ελλαδα, hackers greece, iguru

Written by newsbot

Although the press releases will be from very select to rarely, I said to go ... because sometimes the authors are hiding.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).