{"id":8305,"date":"2022-05-27T12:00:00","date_gmt":"2022-05-27T09:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/2022\/05\/27\/cybersecurity-a-global-problem-that-requires-a-global-answer\/"},"modified":"2022-05-27T12:00:00","modified_gmt":"2022-05-27T09:00:00","slug":"cybersecurity-a-global-problem-that-requires-a-global-answer","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2022\/05\/27\/cybersecurity-a-global-problem-that-requires-a-global-answer\/","title":{"rendered":"Cybersecurity: A global problem that requires a global answer"},"content":{"rendered":"<p><span>Governments around the world are concerned about growing risks of cyberattacks against their critical infrastructure. Recently, the cybersecurity agencies of the countries comprising the \u2018Five Eyes\u2019 alliance <\/span><a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-110a\"><span>warned of a possible rise in such attacks<\/span><\/a><span> \u201cas a response to the unprecedented economic costs imposed on Russia\u201d following the country\u2019s invasion of Ukraine.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>The advisory noted that \u201csome cybercrime groups have recently publicly pledged support for the Russian government\u201d, with the threat of such cyber-operations coming \u201cin retaliation for perceived cyber offensives against the Russian government or the Russian people\u201d.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>According to Andy Garth, ESET Government Affairs Lead, such activity is \u201ca global problem with state actors, and their proxies, with some states willing to provide safe havens in which criminal groups can operate with impunity\u201d. <\/span><span><br \/>\n<\/span><\/p>\n<p><span>\u201cIn the case of the Ukraine conflict, some criminal groups are now engaging in cyberespionage allegedly at the behest of their Russian hosts. Indeed, it\u2019s also prudent to prepare for increased incidents of cybersabotage and disruption as cyberattacks are added to the retaliation toolbox and the risk of spillover increases,\u201d says Garth. There is also a heightened risk of unintended consequences as vigilante groups enter the fray on both sides.<\/span><span><br \/>\n<\/span><\/p>\n<h2><span>A new approach to cyber-resilience<\/span><span><br \/>\n<\/span><\/h2>\n<p><span>Before the invasion, governments across the globe were already considering cybersecurity strategies to counter the ever-escalating cyberthreats from state actors and criminal groups. But the new risks perceived by governments since February are fueling a new urgency towards building cyber-resilience.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>On March 15<\/span><span>th<\/span><span>, US President Joe Biden <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/statements-releases\/2022\/03\/21\/fact-sheet-act-now-to-protect-against-potential-cyberattacks\/\"><span>signed<\/span><\/a><span> the Strengthening American Cybersecurity Act of 2022, requiring companies dealing with critical infrastructure to report substantial cyberattacks to the <a href=\"https:\/\/www.cisa.gov\">Cybersecurity and Infrastructure Security Agency<\/a> (CISA) within 72 hours and all <\/span><a href=\"https:\/\/www.welivesecurity.com\/2021\/07\/08\/ransomware-pay-not-pay-legal-illegal-these-are-questions\/\"><span>ransomware payments<\/span><\/a><span> within one day. More than just a disclosure law, the new regulation is intended to change the perception of a cyberattack from a private company matter to a public threat. This legislation comes as part of a trend, following the <\/span><a href=\"https:\/\/www.welivesecurity.com\/2021\/05\/19\/colonial-pipeline-attack-hacking-physical-world\/\"><span>Colonial Pipeline attack<\/span><\/a><span> in May 2021 when President Biden <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/speeches-remarks\/2021\/05\/13\/remarks-by-president-biden-on-the-colonial-pipeline-incident\/\"><span>signaled<\/span><\/a><span> a new role for cybersecurity and asked for a whole-of-government approach to cyberthreats.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>Together with new powers, CISA is also set to have its budget next year increased to $2.5 billion, which is <\/span><a href=\"https:\/\/www.whitehouse.govhttps\/\/web-assets.esetstatic.com\/wls\/2022\/03\/budget_fy2023.pdf\"><span>an extra $486 million from the 2021 level<\/span><\/a><span>. On top of this, Biden\u2019s <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/statements-releases\/2021\/08\/03\/fact-sheet-top-10-programs-in-the-bipartisan-infrastructure-investment-and-jobs-act-that-you-may-not-have-heard-about\/\"><span>infrastructure bill<\/span><\/a><span> allocates $2 billion to cybersecurity, of which $1 billion is allocated towards improving the cybersecurity and resilience of critical infrastructure.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>In parallel, the European Union has followed a similar path with several new directives and regulations and additional funding aimed especially at enhancing the EU\u2019s cyber-resilience and the role of EU institutions, as well as facilitating greater cooperation between member state bodies. On the operational level, in response to Russia\u2019s invasion, for the first time the EU deployed the <\/span><a href=\"https:\/\/eda.europa.eu\/news-and-events\/news\/2022\/02\/24\/-of-first-capability-developed-under-pesco-points-to-strength-of-cooperation-in-cyber-defence#:~:text=Cyber%20Rapid%20Response%20Teams%20(CRRTs,recognise%20and%20mitigate%20cyber%20threats.\"><span>Cyber Rapid Response Team<\/span><\/a><span> to assist Ukraine with mitigating cyberthreats. <\/span><\/p>\n<p><a  href=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/05\/cybersecurity-global-approach.jpg\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"563\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/05\/cybersecurity-global-approach.jpg\" width=\"1000\"><\/a><\/p>\n<p><span>The EU-proposed <\/span><a href=\"https:\/\/www.europarl.europa.eu\/RegData\/etudes\/BRIE\/2021\/689333\/EPRS_BRI(2021)689333_EN.pdf\"><span>NIS2 Directive<\/span><\/a><span> aims to strengthen security requirements, address the security of supply chains, and streamline reporting obligations. NIS2 also significantly broadens the scope of critical entities falling under mandatory high level security requirements. Sectors such as health, R&amp;D, manufacturing, space or \u201cdigital infrastructure\u201d including cloud computing services or public electronic communication networks will now require stronger cyber-resilience policies. Similarly, the EU Commission is proposing new legislation to focus on the financial sector with the <\/span><a href=\"https:\/\/oeil.secure.europarl.europa.eu\/oeil\/popups\/summary.do?id=1632580&amp;t=d&amp;l=en\"><span>Digital Operational Resilience Act <\/span><\/a><span>(DORA) <\/span><span>and<\/span><span> IoT devices with the Cyber Resilience Act, which will be presented after the summer.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>The need for sharing intelligence and closer cooperation in threat detection is also the underpinning objective of the proposed <\/span><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/joint-cyber-unit\"><span>EU Joint Cyber Unit<\/span><\/a><span>, which aims to protect the EU critical infrastructure against cyberattacks. <\/span><span>While its<\/span><span> exact role and structure are still being decided, it <\/span><span>is expected to<\/span><span> have an operational character <\/span><span>that <\/span><span>ensure<\/span><span>s<\/span><span> a better exchange of intelligence on cybersecurity threats among the Member States, the European Commission, ENISA, CERT-EU, and the private sector. <\/span><span><br \/>\n<\/span><\/p>\n<p><span>The Commission also proposed new regulations to strengthen CERT-EU, converting the structure into the \u201cCybersecurity Center\u201d, with the aim of strengthening the security postures of EU institutions.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>Garth points out that these efforts are a \u201crecognition within governments (and EU institutions) of the scale of the challenge in protecting nation-state digital assets against growing and evolving cyberthreats\u201d. He highlights the need for a \u201cwhole-of-society approach and partnerships with the private sector at its heart\u201d, \u201cno government can address these threats alone.\u201d citing the <\/span><a href=\"https:\/\/www.gov.uk\/government\/publications\/national-cyber-strategy-2022\/national-cyber-security-strategy-2022#pillar-5-countering-threats\"><span>UK\u2019s National Cyber Strategy 2022<\/span><\/a><span> where this kind of collaboration can be seen in areas such as education, building resilience, testing, and incident response.<\/span><span><br \/>\n<\/span><\/p>\n<h2><span>But what risks do governments face?<\/span><span><br \/>\n<\/span><\/h2>\n<p><span>Governments have a unique characteristic: they store all the data concerning their activity as well as their citizens\u2019 data. Therefore, they are a most desirable target. This common threat to states is led at the United Nations level to agree \u201coff limits\u201d areas where cyberoperations should not be conducted, such as healthcare systems. The reality has diverged from this, with an ongoing cybercontest between the major powers and [non-binding] agreements at <\/span><a href=\"https:\/\/www.aspi.org.au\/report\/un-norms-responsible-state-behaviour-cyberspace\"><span>UN<\/span><\/a><span> level being <\/span><a href=\"https:\/\/carnegieendowment.org\/2021\/05\/19\/un-struggles-to-make-progress-on-securing-cyberspace-pub-84491\"><span>ignored<\/span><\/a><span>.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>These contests <\/span><a href=\"https:\/\/www.welivesecurity.com\/2022\/03\/07\/cyber-readiness-face-escalated-gray-zone-conflict\/\"><span>play out in the \u2018gray zone\u2019<\/span><\/a><span> where states can engage each other under the premise of plausible deniability and a constant cat-and-mouse game in the sphere of cyberespionage including stealing of information and attacks on critical infrastructure, sometimes causing real world disruption to <\/span><a href=\"https:\/\/www.welivesecurity.com\/04\/21\/critical-infrastructure-cyberattack-longer-think\/index.html\"><span>entire countries<\/span><\/a><span>. Recent cases such as the use of Pegasus spyware illustrate that eavesdropping is alive and well even among friendly states. As Garth says, \u201csnooping has been around a long time &#8230; as many intelligence practitioners are likely to agree, it can provide useful intelligence with modest risk as long as you don\u2019t get caught.\u201d<\/span><span><br \/>\n<\/span><\/p>\n<p><span><\/p>\n<p> RELATED READING: <a href=\"https:\/\/www.welivesecurity.com\/2022\/03\/07\/cyber-readiness-face-escalated-gray-zone-conflict\/\">Cyber\u2011readiness in the face of an escalated gray zone conflict<\/a>\n<\/p>\n<p><\/span><\/p>\n<p><span>Likewise, targeted <\/span><a href=\"https:\/\/www.welivesecurity.com\/2021\/08\/10\/ransomware-runs-rampant-how-combat-this-threat\/\"><span>ransomware attacks are a growing concern<\/span><\/a><span> \u2013 not only to obtain the largest payout, but to maximize the value of stolen data on well-established criminal <\/span><a href=\"https:\/\/www.reuters.com\/legal\/government\/us-european-partners-announce-takedown-hacker-website-raidforums-2022-04-12\/\"><span>marketplace<\/span><\/a><span> platforms<\/span><span><br \/>\n<\/span><\/p>\n<p><a href=\"https:\/\/www.welivesecurity.com\/2021\/04\/07\/supply-chain-attacks-when-trust-goes-wrong-try-hope\/\"><span>Attacks<\/span><\/a><span> against supply chains can endanger not just government agencies or a specific institution, but critical sectors of a country\u2019s economy. The widespread impact of attacks like <\/span><a href=\"https:\/\/www.welivesecurity.com\/2021\/07\/03\/kaseya-supply-chain-attack-what-we-know-so-far\/\"><span>the one against Kaseya<\/span><\/a><span> make it harder for governments to react, creating truly disruptive consequences for both businesses and citizens. But as some states are content to risk indiscriminate disruption and damage, others launch focused attacks targeting specific industrial units and systems with the aim of knocking out parts of a nation\u2019s critical infrastructure.<\/span><span><br \/>\n<\/span><\/p>\n<h2><span>Getting everyone to work together is the real challenge<\/span><span><br \/>\n<\/span><\/h2>\n<p><span>Governments don\u2019t have an easy job, maintaining legacy systems, tackling skills shortage, building cyberawareness in the workplace, managing an expanding attack surface area, integrating new technologies, and facing down sophisticated attacks. Preparedness takes time and there is need to adopt a <\/span><a href=\"https:\/\/www.welivesecurity.com\/2021\/07\/23\/protecting-hybrid-workplace-zero-trust-security\/\"><span>zero trust approach<\/span><\/a><span>, understanding that attacks will happen and must be mitigated where they cannot be avoided. <\/span><span><br \/>\n<\/span><\/p>\n<p><span>This is hard to apply the typically multi-layered infrastructure of government offices. Despite their size, it is often easier to protect the systems of centralized authorities but dealing with the immense number of local and devolved offices turns this into an almost impossible mission. Despite gradually increasing funding, there are too few cybersecurity professionals, making it much harder to defend against the evolving threats.<\/span><span><br \/>\n<\/span><\/p>\n<p><span>Citizens are increasingly aware of cyberthreats, often due to high profile and frequent reports in the media; keeping the spotlight on the problem, funding awareness programs \u2014 particularly those aimed at the less tech-savvy and the vulnerable \u2014 is critical to success. Even so, humans making mistakes continues to be the major entry point for cybercriminals, which is why taking advantage of developments in machine learning and artificial intelligence is now essential, typically deployed in products and services like EDR and real-time threat intelligence.<\/span><span><br \/>\n<\/span><\/p>\n<h2><span>A common problem requires joint action<\/span><span><br \/>\n<\/span><\/h2>\n<p><span>Synergies between the public and private sector come as a much-needed reaction to the growing threat presented by cyberattacks. The Ukraine crisis and previous work done to protect Ukrainian critical infrastructure is an important example of what can be <\/span><a href=\"https:\/\/www.welivesecurity.com\/2022\/04\/12\/industroyer2-industroyer-reloaded\/\"><span>achieved<\/span><\/a><span>. <\/span><span><br \/>\n<\/span><\/p>\n<p><span>In parallel, Garth suggests involving organizations such as the UN, OECD and groups like the G7, G20 dynamically, so that \u201cthe international community shines a spotlight on state cyberactivity, calling out and taking action where necessary against those that ignore established norms and cracking down on criminal groups and their ability to monetize their criminal endeavors &#8230; but also works together to enhance cyber-resilience across the globe, including in developing countries\u201d.<\/span><span><br \/>\n<\/span><span><br \/>\n<\/span><\/p>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/2022\/05\/27\/cybersecurity-global-problem-requires-global-answer\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New and exacerbated cyber-risks following Russia\u2019s invasion of Ukraine are fueling a new urgency towards enhancing resilience<\/p>\n","protected":false},"author":5,"featured_media":8306,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2879],"tags":[],"class_list":["post-8305","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8305"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8305\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8306"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8305"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}