Cyber Risks in the New Normal

02/09/2020
|

User exposure online, both at a corporate and personal level, is ever-increasing. Furthermore, the Spanish lockdown due to the pandemic has increased our work-from-home activity, and cyberattacks on individuals and companies have considerably increased. Below, we will analyze the Cyber Risks in the New Normal:

onbranding-cybersecuritySource: elpais.com

We find two sufficiently strong reasons that would explain this phenomenon: the disorderly and forced implementation of remote work, and the increased use of online channels for personal use during the day, much more focused on e-commerce, banking transactions, and sensitive and personal information inquiries on official agency sites, such as SEPE.

But this strange situation of mandatory confinement ended months ago, so what are we facing now?

Experts and media like to use the well-known term “New Normal.” In this new situation, we are clearly and rapidly exposed to cybercriminal attacks, due to several fundamental reasons:

  • Increased activity on social networks, possibly due to a lighter workload and more time spent at home.
  • Increased online shopping.
  • The establishment of full remote work or hybrid work, which encourages the use of sensitive content on home networks and devices.
  • The vulnerability of companies to cyberattacks, due to inadequate preparation and lack of investment in these areas.
  • The general public’s lack of awareness regarding cybersecurity protection and risks.

These conditions create the perfect breeding ground for potential attacks and for becoming a target for cybercriminals.

But what risks are we really facing?

Phishing.

Phishing is one of the most current cyber risks. It is a technique that involves deceiving the user by providing a link that leads to a supposed official site, where they are asked to fill in sensitive data.

If the user accesses it, they fall for the trap, and come to believe that the origin of the message and the website are official and secure, providing cybercriminals with sensitive information such as banking credentials, social media access passwords, and any other type of personal information.

The most common channels for disseminating these links are email, especially corporate email (for example, simulating an email from the HR department announcing a false dismissal and redirecting to a link), or via SMS. Numerous warnings reach us from the State Security Forces through their social networks.

onbranding-cybersecurity

onbranding-cybersecurity

Sending infectious content via corporate email.

Corporate email is an easy target for cybercriminals, due to companies’ lack of cybersecurity knowledge and the absence of elements and tools to prevent illicit access to systems. Lack of protection is one of the biggest problems faced by Spanish companies.

The main attack method for this cyber risk is through the mass sending of malicious emails, i.e., with attachments (usually in executable .exe format or an Excel file) whose download and opening automatically installs a computer virus.

onbranding-cybersecuritySource: europapress.es

Ransomware.

Another objective that cybercriminals may be seeking is quick financial gain. This type of attack uses data encryption of the victim, meaning the victim’s inability to access their own content (data kidnapping), in exchange for financial compensation to release it.

The content they typically access consists of intimate and private photographs, or sensitive corporate or personal information.

Companies and Celebrities are continuously exposed to different cyber risks. They are easy targets for criminals due to their purchasing power and the potential consequences for their reputation.

How to prevent cyber threats?

  • Install certified and recognized anti-malware software on all corporate and personal devices.
  • Be wary of unexpected SMS messages or emails from courier companies, official bodies, etc.
  • Verify the authenticity and security of the site you are accessing, confirming that it is official and secure via the HTTPS protocol.
  • Download Apps only from official marketplaces (Google Play and App Store).
  • Encrypt corporate email and files.
  • Distrust unknown senders, and if the message contains attachments, do not open it.
  • Activate the anti-spam filter on servers and email providers.
  • Block the installation of programs from unknown sources in your smartphone settings.
  • Back up your data regularly.
  • Pay attention to the extension of the files you open and install. Disable the option in Windows to hide known file extensions.
  • Update your device software when prompted.
  • Avoid public or unsecured Wi-Fi networks.

We offer a large amount of sensitive and private information that, if accessed for malicious purposes, can cause serious problems for our finances or reputation. The attacks we can fall victim to represent a security breach that can almost completely paralyze a business or cause incalculable damage to a user’s reputation.

It is as important to have software that protects us from malicious actions as it is to be cautious and understand what we face in the online environment. Only then can we avoid being an easy target for a cyberattack online.

If you have suffered any attack on the security of your devices, passwords, or files, or know someone with problems, contact us.

At onBRANDING, we are experts in Cyber Investigation, Digital Identity, Online Reputation, Privacy and Cybersecurity, corporate and personal digital identity protection, and protection of protected witness identity.

Digital Identity

Methods for analyzing and
assessing online
reputation damage