Intelligent SME.tech Issue 03 | Page 30

intelligent

// FEATURE //

Kyle Turner , Cyber Security Lead UAE at A & O IT Group

MAKING SURE EMPLOYEES ARE EDUCATED ON HOW TO SPOT CYBERTHREATS THAT HIT THEIR INBOX IS VITAL
FOR SMES . anticipate that many of these automated spear phishing attacks will prey on fears around the pandemic , politics and the economy .
Cloud-hosting providers finally crack down on cyberabuse
Phishing attacks have come a long way from the 419 ‘ Nigerian Prince ’ scams of old . Threat actors now have an abundance of tools to help them craft convincing spear phishing emails that trick victims into giving up credentials or installing malware . Lately , we ’ ve seen them leverage cloud hosting to piggyback on the otherwise good reputation of Internet giants like Amazon , Microsoft and Google .
Most cloud-hosting services like Azure and AWS offer Internet-accessible data storage where users can upload anything they ’ d like , from database backups to individual files and more . These services are exposed to the Internet through custom subdomains or URL paths on prominent domains such as cloudfront . net , windows . net and googleapis . com .
Threat actors commonly abuse these features to host website HTML files designed to mimic the authentication form of a legitimate website like Microsoft365 or Google Drive and to steal credentials submitted by unsuspecting victims .
This style of phish is effective because the email links to spoofed forms that resemble legitimate Microsoft , Google or Amazon AWS links with domains owned by those companies . In 2021 , we predict that these cloud-hosting providers will begin heavily cracking down on phishing and other scams by deploying automated tools and file validation that spot spoofed authentication portals .
2021 technology priorities for SMEs
Kyle Turner , Cyber Security Lead UAE at A & O IT Group
Due to the new normality of working from home , the landscape for attackers has changed . The original corporate spending to secure office networks is now practically pointless due to everyone working from home . Not to mention most home routers have not been patched . This new landscape is not only leaving the employee vulnerable , but hackers will also now be able to access their family ’ s data through the home Wi-Fi that they all use .
In addition , as we know , children are less tech savvy , so if they receive a dodgy email to a free game for example , they are most likely going to click it . As an organisation your last line of defence is the people that work for you . Making sure employees are educated on how to spot cyberthreats that hit their inbox is vital for SMEs because , despite phishing having been around for over 10 years , it is still the most successful and common attack method out there .
Another upcoming technology area is AI . With AI you can now get technology to make videos that look like people are saying things they wouldn ’ t , for example spoofing someone ’ s voice . You can even carry out an attack where you spoof a person ’ s voice , in order to gain entry to sensitive systems and bank accounts that are using a voice recognition authentication mechanism .
Attackers started using AI long before defenders did , so now it ’ s become a game of cat and mouse . The defenders can never get ahead because they are chasing their own tail and the hackers already know what is going on from sharing tips and tricks on forums between each other . Due to SMEs ’ more limited financial options , many feel an investment in AI may not be worth the large sum it costs to implement . Backing this up is a recent report which showed that the uptake of AI solutions within SMEs has been slow , with a 4 % adoption rate .
However , Venture Beat states that automated cybersecurity processes are especially useful for smaller organisations as they can act in tandem to IT staff and allow them more time for other parts of the business . For example , we ’ ve seen a surge in AI now replacing analysts as it is more reliable . People can make mistakes , but computers rarely do .
Lastly , I would state that data privacy is becoming increasingly important now . We ’ re seeing more and more fines and penalties associated with breaches but it ’ s also becoming more complex with regulations such as GDPR . Being able to track the data and secure it properly is essential so that it doesn ’ t fall into the wrong hands .
30
. tech
Intelligent SME . tech