Cyberattacks on businesses could have increased by up to 2000% from 2018 to 2019, according to the IBM “X-Force Threat Intelligence Index 2020” report. Furthermore, Interpol warned in August of this year about the increase in cyberattack cases during the pandemic.
Activity against companies and healthcare infrastructures is particularly alarming. One of the cases that took place in Spain is that of Quirón Salud. When citizens’ health is at stake, we become aware of the relevance and escalation that an attack on the IT systems of a vital infrastructure can entail.
These cyberattacks are compounded by industrial espionage carried out by Governments and Pharmaceutical companies against other companies and laboratories in the sector. As early as July 2020, the digital newspaper “La Información” ran the following headline: “The Covid vaccine threatened by pharmaceutical ‘cyberespionage’”.
Any company can fall victim to cybercriminals through various sophisticated techniques, increasingly adapted to user behavior.
On rare occasions, the response to a cyberattack is correct. Generally, the decisions made regarding it are not the most appropriate.
Cyberattacks and cyber risks faced by companies.
The internet and the growing digitalization of the business world open new lines of business, which indirectly leads to the emergence of risks that must be understood, prevented, and managed. To explain this reality more clearly, we must differentiate these two key concepts:
- A cyberattack can be defined as a malicious attempt carried out by an individual or organized group, through which they can break into a target’s information systems. Generally, the attacker seeks some type of benefit, whether economic or reputational.
- Cyber risk exposes the threats and dangers arising from the use of new technologies in the business environment, with the network being a common channel for information and communication in a company’s or entity’s daily operations. Here, the important thing is to understand the risks and prevent their occurrence, thereby facilitating the establishment of technical and organizational measures whose main objective is to minimize their impact.
Ultimately, these two concepts feed into each other and go hand in hand, as cyberattacks are behind a large part of the cyber risks that companies face today.
According to the Spanish Observatory of Cybercrimes, it is estimated that around 218,302 cyberattacks occurred in Spain in 2019, with Catalonia, the Community of Madrid, and Andalusia topping the list as areas with the highest incidence of cyberattacks. And to this figure, we must add all those cyberattacks that have not been reported, both at the company and individual level. In the Covid era, attacks have multiplied, so this figure could increase alarmingly in 2020.
The economic impact of a successful cyberattack is evident, but we must not forget that they also have a strong impact on a company’s reputation, which ultimately jeopardizes the survival of Spanish companies that do not implement the necessary measures to face this reality.
What are the most common cyberattacks and their impact on the Spanish business fabric?
The most common cybercrimes faced by Spanish companies are:
- Computer fraud: all kinds of scams and deceptions are carried out via the internet that in another era used more traditional methods, mainly of an economic nature.
- Direct threats or coercion, carrying out personalized offensives that affect a company’s reputation in exchange for economic benefit, and even transforming the entity’s usual operations to achieve an ideological or business objective.
- Computer forgery, involving the manipulation of programs, applications, and even data. A clear example is the modification of a digitized document, altering information in search of benefit.
- Unlawful access to networks and systems, where cyberattackers exploit vulnerabilities and “backdoors” to gain unauthorized access, generally in search of valuable information or service disruption.
- Attacks against honor, which violate the dignity and reputation of an individual or a company, tarnishing and attacking their image through the internet.
- Cybercrimes against intellectual and even industrial property, including the theft of patents and essential confidential information, among others.
- Crimes of a sexual nature, in which a company’s image can be affected after personal manipulation, for example, of the CEO. Attackers use blackmail methods of a sexual nature in search of a serious impact, using videos or images of the victim, or even interfering with explicit pornography after hacking an individual’s device.
After the cyberattack: what your company should (and shouldn’t) do.
Typically, when a company or celebrity falls victim to a cyberattack, they usually seek the help of a specialized agency to strengthen their IT systems, recover access to their devices and information, and remove leaked content.
These actions form the basis for restoring normalcy and continuing operations, attempting to avoid even greater economic losses.
However, it doesn’t end there. It is necessary to work beyond the obvious to try to resolve the situation and minimize damage to any affected customers.
When a company suffers a security breach that affects the intimacy or privacy of customers, it must inform them and guarantee their security, above all else.
It is common to find cyberattacks on corporations or administrations whose customer data is available on the Deep Web, and even forms part of economic transactions for those willing to pay for this data.
How to act after being a victim of a cyberattack?
We identify three fundamental courses of action when we detect that we are victims of cybercriminals, and their actions can seriously harm the company and its customers:
- Restoring normalcy.
This is the basic course of action that all companies take when they fall victim to a cyberattack. It goes without saying why it is important to prevent cybersecurity incidents and strengthen protection and attack detection systems; but if cybercriminals have managed to reach the heart of our company, it must be resolved as soon as possible.
The objective of this approach is to regain control of IT systems and return to normalcy as quickly as possible.
- Customer communication.
Communication with customers is essential at this point, due to the potential vulnerability of the information the company holds about them. Failure to inform those affected is a practice far removed from all business ethics.
A comprehensive communication strategy must be implemented to inform customers of the incident, especially if a security breach may have occurred that partially or totally affects their private data. If the cyberattack has compromised this type of data, it could pose a risk to customers’ freedoms, privacy, and rights.
We can grasp the seriousness of a customer data leak if we consider institutions that care for minors, mental hospitals with recorded patient sessions, or banking credentials and access for e-commerce customers.
The sale of this type of data on the Deep Web can pose serious dangers to victims, as postal addresses, phone numbers, family data, health information, banking data and access, and endless content could be exposed, which in the wrong hands can lead to a serious crime or offense.
Therefore, a customer communication plan should be developed that includes:
- Information on the number of affected customers
- The type of data exposed.
- The measures that will be taken to eliminate the information that has been made public.
- The measures taken to strengthen systems.
- Phone number or direct contact channel to obtain information about the situation.
- Contact person responsible for communication with customers.
It is not enough to inform customers of the situation; measures must be taken to mitigate the effects it may have on them.
- Reputational crisis management.
A cyberattack that compromises customer data and security can quickly lead to a reputational crisis for the company or institution that has been a victim of the incident.
It is common for the organization’s name and the effects of the attack to dominate headlines for a while, and for customers themselves to generate content about the concern the situation creates; and also, about the company’s possible inaction before and after the cyberattack.
This inaction can worsen the company’s reputational situation. To begin to manage a crisis from the outset, the following measures must be taken:
- Take measures to restore the situation.
- Develop a communication plan for customers, and report the facts and measures taken.
- As far as possible, prevent customer data from remaining public, and continuously report on the actions taken to achieve this.
- Inform the media about the situation before they start to publish any headlines. It is important to emphasize that efforts are underway to resolve the situation.
- Notify the Spanish Data Protection Agency within 72 hours.
- Report to the Police, Civil Guard, etc.
- Develop a new brand image and reputation plan to follow after the incident is resolved.
Speed in response and transparency in communication are fundamental, as is communication and customer service during such a delicate time. It is essential to keep communication lines open, avoiding technical jargon that confuses or generates insecurity, and to explain in detail how the problem will be solved.
Ignoring the problem without addressing it can lead to an even more serious situation, implying irreparable reputational damage with all that entails.
The latest detected cyberattacks.
Almost daily, news breaks about cyberattacks on companies and entities. The ways of reacting vary greatly, but press reports usually do not identify how the company is acting to resolve the situation.
Below, we review some cyberattacks that have made headlines in recent months, reflecting the complex situation that companies, institutions, and celebrities can face:
https://www.larazon.es/deportes/20201121/4dqnyxswazf7lbu63qpxedznre.html
https://www.elperiodico.com/es/sociedad/20200918/hackers-china-datos-vacuna-espana-covid19-8117592
These headlines from the last three months represent a small sample of the risks users are exposed to in the digital environment.
Furthermore, they make us reflect on the need to manage a cyberattack responsibly, as in almost all of them, we can glimpse the vulnerability that customers or partners of the companies have suffered due to the attack.
Who can help you in case of a Cyberattack and reputational crisis?
Cyberattacks are constant, evolving, and cause a great impact not only at an individual level but also at a business level.
100% security does not exist, but we must apply sufficient technical and organizational measures to minimize the impact of a threat. Cybersecurity is still perceived as an expense and not as an investment. This provides incredibly easy and profitable access for cybercriminals.
Who can help protect my company?
The first thing we must do is establish a strong cybersecurity culture within the company. To do this, we will implement training and awareness plans that address the main vector for an attack: the user themselves.
There are companies specialized in the personalized creation of educational programs around information security. This will strengthen basic knowledge and good practices for prevention and defense among employees themselves.
Regarding technical measures, which can sometimes be a headache, it is essential to have technological and IT support and advice from specialists. This way, security can be established in the company’s systems.
And we must not forget legal security. The application of international standards and essential regulations, such as the GDPR for data protection, will prevent future sanctions. They will also facilitate the establishment of security policies and procedures.
We must also consider the importance of a consultancy or specialized company that manages the process. We must also work continuously to prevent, detect, resolve, and restart the cycle. The same applies to establishing contingency and business continuity plans.
Cybersecurity as an investment, not an expense.
We must begin to see Cybersecurity as a priority and essential investment for the well-being of businesses themselves. A lack of resources or awareness in this area can lead to a strong impact that could jeopardize the continuity of the service provided.
It’s not just about curing once the damage is done. It’s about applying sufficient measures to foresee, resolve, and minimize potential damage from a cyberattack.
If the damage is already done, we must seek active and passive solutions with the help of specialists in the field. It is crucial that the situation caused by a threat does not recur.
Sec2Crime, onBRANDING’s partner in security matters, has collaborated in the preparation of this post. From their experience, they have provided key insights and knowledge in cybersecurity and cyber risks. If you want to know more about their project, access their website via this link.
At onBRANDING, we specialize in cybersecurity, cybercrime investigation, crisis communication management, reputation, digital identity, and legal advice.
If you have been a victim of an attack or illicit access to your communications, we work to restore normalcy.