Cybergeddon is Upon Us

Cybergeddon is Upon Us. The End is Near 

Liked this post? Share with others!

It doesn’t have to be. 

About a year ago I wrote that cyber resilience wasn’t a technology trend. It was a business necessity.

Twelve months later, I wish I’d been wrong.

In the last year we’ve watched some of the UK’s biggest organisations brought to their knees by cyber criminals. Household names, including Marks & Spencer, Jaguar Land Rover, Co-op and Harrods, all suffered significant cyber incidents, disrupting online services, payment systems, production lines and operations. The impact wasn’t measured purely in stolen data, but in lost revenue, damaged reputations, frustrated customers and weeks of operational disruption.

The reported financial impact has been into hundreds of millions of pounds, with this reflecting in quarterly GDP numbers. This does not even take into account the hundreds of small businesses who have suffered catastrophic damage from successful cyber attacks. The ones that do not make the news but the effects are even worse for the business owner who suffers them.  

These examples should have served as a wake-up call to every business, regardless of size, but many are still ignorant to the size of the risk they are facing. 

Cyber criminals don’t discriminate, they simply look for the easiest way in.

What’s changed over the past year isn’t just the volume of sophisticated attacks. It’s the ability for the non-skilled malicious actor to launch highly sophisticated attacks with zero knowledge. 

Artificial Intelligence has accelerated the threat landscape faster than most organisations have been able to respond. AI can now write convincing phishing emails, clone voices, create deepfake videos, automate reconnaissance and dramatically reduce the time it takes attackers to identify vulnerabilities. The barrier to entry for cybercrime has never been lower.

In recent weeks several commercial, and supposedly secured and protected, AI models have freed themselves and successfully completed fully automated cyber attacks against real businesses. This is not a simulation

Now please think for a minute what this means when the same capability is freely available in open source models. It is not science fiction, it will be available before the end of the calendar year. 

These are not new attack methods, they are faster, automated and can be delivered with no skill, at scale. 

That’s why cybersecurity has never been purely a technology problem, it is a business problem.

Another misconception we still encounter is the belief that if a business has outsourced its IT, it’s automatically secure. It isn’t.

IT and cybersecurity are two very different disciplines. Your IT provider keeps your business running. They ensure systems are available, users can work and infrastructure performs as expected.

A cybersecurity partner assumes that attacks will happen and focuses on preventing them, detecting them quickly and ensuring your business can continue operating when they do.

Those are not the same thing.

Unfortunately, the cybersecurity industry doesn’t always help itself. Every week there’s another vendor claiming to have the latest AI-powered platform, revolutionary dashboard or miracle solution that promises complete protection. They provide a false sense of security as they focus on one risk, convincing the non-technical business owners into believing that by watching their endpoints they are secure. 

They use the 24X7 monitoring as the clincher, letting you think they are watching your endpoints and users 24 hours a day. How many of your users have the devices on 24 hours a day? 

Will this miracle cure tell you that there is a stolen session and the attacker is living in your cloud service, re-routing emails, moving data or planting malicious content on your infrastructure? 

When the credentials have been given away, without visibility, your shiny cyber security tool will be blind to it. This is part of the reason the average breach takes close on 200 days to be discovered.

Technology matters, but people, processes and preparation matter just as much.

That’s why at J2 Software we’ve always taken a layered approach to security.

We combine full network visibility, managed detection and response, continuous monitoring, user awareness training, phishing simulations, vulnerability management and cyber resilience planning to create multiple barriers between attackers and our customers. 

We also believe in validating security rather than simply trusting it.

Whether that’s deploying deception technologies such as honeypots to detect attackers early, stress-testing environments or educating users before criminals do, our focus has always been on making businesses harder targets.

Business leaders also need to start asking better questions of their security providers.

Don’t ask what technology they sell; 

  1. Ask how quickly they’ll detect an attack?
  2. Ask who is monitoring your environment at two o’clock in the morning and do they know anything about your business? 
  3. Ask what happens when, not if, someone clicks the wrong link and provides their credentials? 
  4. Ask how they’ll help your business recover?
  5. Most importantly, ask whether they’re talking about resilience or simply prevention.

No organisation can honestly promise you’ll never suffer a cyber attack. Real cyber security partners will tell you the truth.

Our job isn’t to promise perfection, it’s to minimise risk, detect threats quickly, limit damage and keep you operational.

Cybersecurity is one of the defining business risks of our generation and the organisations that thrive over the next decade won’t necessarily be the ones with the biggest cyber security budgets, they’ll be the ones that recognise cyber security isn’t an add-on, a compliance exercise or an insurance policy.

It’s a core business capability.

The last year has shown us exactly what’s at stake.

The only real question now is whether businesses choose to learn from someone else’s cyber attack or will they wait until it’s their own?

If any of this raises questions, message me and we can talk through it. 

author avatar
John Mc Loughlin Director
John Mc Loughlin is a cybersecurity and digital resilience specialist with experience in email security, phishing mitigation, and data protection strategies. He works with organisations to reduce digital risk and improve operational resilience.

Request Consultant