Skip to main content

What the Hack? February 2022

Page 1

What the Hack? February 2022

www.seconcyber.com


Secon

02

February’s top news. Secon welcomes first class of our Cyber Academy We welcomed the first group of cadet security engineers into our Cyber Academy training program this month. In December, we announced our partnership with St. Paul University Philippines (SPUP) to deliver an internship program that aims to train the next generation of cyber professionals. As part of this technical transition program, cadets receive a thorough immersion into the world of cyber security and gain the opportunity to develop their skills within a structured, experienced-based program. Each student will undergo a six-month training program with our team of cyber security experts so they can have the best possible start to their career in cyber security. The first group of trainees consists of five final year students from SPUP. This small group size ensures that each cadet will be able to receive close mentoring from Secon’s security engineers. By the end of the course in June, outstanding cadets will receive job offers from Secon to join our security operations centre (SOC). We also have plans to further expand this course to professionals in the future to help those already in the IT industry to explore or transition to a career in cyber security. To read more about our Cyber Academy, click here.

Meet Crez, our new Philippines General Manager Crez Isaguirre has joined Secon as our General Manager in the Philippines. This new position aims to strengthen and expand our existing presence in the Philippines. As General Manager, Crez will lead and grow our Philippines operations as we continue to expand our managed security services. Crez will also take on the role of Corporate Social Responsibility (CSR) champion and ambassador to help drive and promote our CSR agenda. Crez has a degree in Business Management and has over 20 years’ experience in leading customer operations in the BPO, finance, and consulting industries. Before joining Secon, Crez worked for Ernst & Young, J.P. Morgan, and Stream Global. Crez said, “I’m very excited to be joining Secon and to be part of supporting the growth agenda. Philippines has a great pool of talent especially in cyber security and I am looking forward to working with the team to build on our strong and credible foundation.” You can read more about Crez’s appointment here.


What the Hack? - Feb 2022

Addressing the Minimum Cyber Security Standard. Webinar and checklist In February we ran a series of webinars on how organisations can address the government’s Minimum Cyber Security Standard with Zero Trust. In the webinar, Chief Security Evangelist Andrew Gogarty outlines the principles of Zero Trust and explains how it addresses the issues presented by VPNs. If you missed the webinar and are curious how Zero Trust can help you enable secure remote working and eliminate your attack surface, you can click below to watch it on-demand.

If you’re also interested in how else you can optimise your security to meet the Minimum Cyber Security Standard, we’re here to help. The Minimum Cyber Security Standard provides a checklist of basic controls that organisations should have in place to protect themselves from cyber attacks. By having all its controls in place, an organisation has the minimum level of cyber security defences that will keep it protected from the most common cyber security breaches. To help you organise your thoughts when assessing your current level of security, we’ve prepared a checklist which includes the government’s controls and additional items we feel both complement them and are imperative for organisations who have transitioned to remote working. Click the button to download the checklist. If you have any questions about how Secon can help you address any of the controls, please email one of our Security Advisors at hello@seconcyber.com or contact us here.

03


Secon

04

Top 10 cyber security trends for 2022. Insight recap Do you have the right risk reduction activities on the cards for 2022? In our most recent report, Chief Security Evangelist Andrew Gogarty set out his top security trends for 2022. You can see a brief overview of the report below, but if you’d like to download the full version, click here.

1

Ransomware Ransomware continues to impact organisations and remains an ongoing concern. Many organisations have already matured their backup and recovery approaches over the last few years, but this doesn’t mean that organisations shouldn’t stop thinking about ransomware.

2

Cloud breaches As cloud adoption continues to increase throughout 2022, we expect to see an increase in unauthorised access and data breaches due to avoidable security gaps presented by misconfigurations and human error.

3

Vulnerability exploits The growth in zero-day exploits is likely to become a bigger problem for security operations teams to manage going forward. As a result, we expect to see an increased adoption of Zero Trust in 2022 to help organisations eliminate their attack surface, control access to their data, and prevent lateral movement of threats.

4

Exact domain name impersonation phishing Since it requires little effort for threat actors, we anticipate an increase in the usage of exact domain impersonation phishing emails. As more organisations move to a DMARC policy of ‘reject,’ we can expect to see in an increase in lookalike domain phishing.


What the Hack? - Feb 2022

5

05

Cyber skills shortage Resource constraints can limit an organisation’s ability to reduce risk, detect, and respond to cyber threats. We expect an increase in the number of organisations outsourcing security operations tasks to help improve their cyber resilience and enable constrained resources to focus on organisational priorities.

6

Insider threat Disgruntled employees and accidental mistakes can cause data breaches. We expect to see an increase in organisations leveraging user and entity behaviour analytics (UEBA) solutions in 2022 to improve their capability in detecting and preventing insider threat activity.

7

Supply chain attacks The supply chain remains an attractive target for criminal actors. This places a need on organisations to extend their risk management activities out to their suppliers through 2022 and beyond. We expect to see more scrutiny in supplier cyber security questionnaires moving forward.

8

State-sponsored activities Cyber attacks are expected to play a greater role in global conflicts. With innumerable and untold covert cyber espionage skirmishes launched to grasp sensitive information and peek at government and defence infrastructures, government funded hacking operations will continue into 2022 and beyond.

9

Fake news and misinformation As numerous events start to come back, we can expect to see more fake news campaigns, troll and bot accounts, and rogue marketing distributed through social networking sites and emails. Fake news and misinformation aren’t only a problem for the government; fake news is also used to lure victims to malicious websites.

10

Cyber insurance More organisations will invest in cyber security insurance during 2022. We expect the process to go beyond a paper-based tick box exercise; an increase in checks and validations will be made by insurers to see how companies address cyber risk and vulnerabilities.


Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707

www.seconcyber.com


Turn static files into dynamic content formats.

Create a flipbook
What the Hack? February 2022 by Secon - Issuu