The Human Hack Defending Against Social Engineering

The Human Hack: Defending Against Common Social Engineering Techniques

Hackers are Exploiting People, Not Just Systems.

The foundational pillars of any organisation’s performance and resilience are people, processes, and technology. These elements are emphasised in the ISO 27001 framework, which underscores the importance of a holistic approach to information security management.

Despite robust technological defences and well-defined processes, it is often the human element that remains the most vulnerable. Social engineering usually involves manipulating or deceiving individuals into divulging credentials or granting some form of unauthorised access to malicious actors.

This article explores the pervasive threat of social engineering, exploring its techniques, real-world impacts, and strategies to fortify your defences against these sophisticated attacks.


What is Social Engineering?

Social engineering is a manipulation technique that exploits human psychology to gain access to confidential information or systems. Unlike technical hacking, social engineering relies on human interaction and often involves tricking people into breaking normal security procedures with the goal of obtaining sensitive information or unauthorised access.

Social engineering tactics are diverse and continually evolving. Some of the most common techniques include:

  • Phishing: Deceptive emails or messages designed to trick recipients into providing sensitive information.
  • Baiting: Offering something enticing to lure victims into a trap.
  • Pretexting: Creating a fabricated scenario to steal victims’ personal information.
  • Tailgating: Gaining physical access to restricted areas by following someone with legitimate access.
  • Vishing: Using phone calls to trick victims into divulging information.

How Common is Social Engineering?

Social engineering is alarmingly common in cyber-attacks. According to findings from American-based Software and Cyber Security company Splunk, in 2023, 98% of all reported cyber-attacks involved some form of social-engineering, making it one of, if not the most prevalent methods used by cybercriminals and other threat actors. An average organisation can face over 700 social engineering attacks annually. [source: Splunk]

Phishing remains the most common social engineering technique, with millions of phishing emails sent daily around the globe. In the UK the 2024 Cyber Breaches Survey indicated that 84% of businesses and 83% charities have been targeted by phishing attacks this year already, with some cyber criminals impersonating other organisations in emails or online. [source: UK Government]

Real World Story – CyberLab Red Team

Tailgating into a Client’s Office

During a Red Team engagement, the team conducted thorough reconnaissance to understand staff reactions to access requests and building entry protocols. Exploiting this knowledge, a team member, posing as an employee on a phone call, approached a side entrance used primarily for Cycle to Work traffic. Waiting for an employee to open the door, the team member tailgated inside. When questioned by a security guard, he flashed a fake pass from his pocket. The presence of this card, combined with the confident demeanour was enough to convince the guard to allow the team member access.

Inside, the team member followed an employee into a lift that required keycard access. By closely shadowing the employee and engaging in light conversation, he gained access to the lift and descended to the basement. Here, most lifts required keycard activation, but one lift did not. Testing it, he found it led directly to the main lobby beyond the security barriers. Coordinating with a colleague, they both used this lift to bypass the barriers.

At the main lobby, they noticed another lift with the desired floor selected. Joining an employee in this lift, they engaged in friendly conversation, further establishing their legitimacy. On reaching the floor, they followed the employee to an office door requiring keycard access. Mentioning the company name, they tricked the employee into letting them in. Inside, they found a coffee machine and various unlocked meeting rooms. Booking a meeting room for an hour provided them with a secure space to operate.

This exercise demonstrated how effective social engineering techniques, such as tailgating, confident interaction, and exploiting human trust, can bypass robust security measures and gain unauthorised access to sensitive areas. The client was subsequently informed of the successful infiltration, highlighting vulnerabilities in their security protocols so that they could take remedial action to harden the physical security protocols and policies and also educate their staff to be more vigilant.

Learn About Red Teaming

Social Engineering Examples

Notably, recently reported threat actor behaviours have highlighted the significant role of social engineering in cyber-attacks. For example, Microsoft have recently reported how a threat actor group known as Storm-1811 are using Microsoft Teams as a vector to target users. The threat actors contact the targeted users via Teams impersonating IT or help desk personnel. This would then lead to the threat actors exploiting Quick Assist, followed by credential theft using EvilProxy, then executing batch scripts, and using SystemBC for persistence and command and control. [source: Microsoft]

In another example, Checkpoint Software Technologies have recently identified 1,200 new domains associated with Amazon, 85% of which were flagged as malicious or suspicious. Some examples of theses discovered domains include:

  • amazon-onboarding[.]com: a brand-new domain designed to steal carrier-related credentials
  • amazonmxc[.]shop: This domain masquerades as Amazon Mexico and even has a similar layout. However, it reveals user login credentials to cybercriminals when entering them in
  • amazonindo[.]com: Like the fake Amazon Mexico domain above, it also reveals user credentials to cybercriminals when entered

Amazon Prime day is very popular event where Amazon give away huge discounts and offers, attracting millions of users globally. This makes it a popular target for cyber criminals and combined with increasingly sophisticated phishing techniques and convincing malicious websites, there is a much higher potential for customers to be scammed. [source: Cyber News]

AI-Driven Social Engineering

Looking to the future, the integration of AI into social engineering is likely to result in even more sophisticated and automated attacks. As we have touched on in previous blog posts, we have already seen how AI and deepfake technology is being used offensively by malicious actors for social engineering purposes, whether to convey misinformation and create social unrest or to assist threat actors in obtaining unauthorised access or sensitive information.

One particular example involved cyber criminals using deepfake AI to extract millions of dollars from a multi-national company based in Hong-Kong. The cyber criminals achieved this by using deepfake generated images and audio of the company’s Chief Financial Officer, and other employees, to stage a conference call where they convinced and instructed another employee to transfer funds equivalent to almost £20 million. [source: Ars Technica]

As AI continues to evolve, we can expect to see the following developments:

  • Hyper-Personalisation: AI will enhance the ability to tailor attacks to individual targets, making phishing emails and other forms of communication indistinguishable from legitimate ones.
  • Real-Time Adaptation: AI-driven attacks will be able to adapt in real-time based on the target’s responses, increasing the likelihood of success.
  • Scalability: AI will enable attackers to conduct large-scale social engineering campaigns with minimal human intervention, increasing the reach and impact of these attacks.
  • Deepfakes: AI-generated audio and video deepfakes could be used to impersonate trusted individuals, further enhancing the credibility of social engineering attempts.
  • AI-Powered Fraud: According to a report by Onfido, deepfake/AI fraud attempts in the US surged 3000% in 2023 from the previous year. These fraud attempts can range from face-swapping or ‘morphing’ apps to bypass facial recognition and verification, AI generated voice replication to impersonate an intended victim or authority figure, to AI generated fabricated images or video of a damaged vehicle or property as evidence in support of fraudulent insurance claims. [source: TNW]


Protecting Against Social Engineering

To best defend against social engineering attacks, organisations and individuals must adopt a multi-faceted approach that addresses various aspects of cyber and physical security. Here are some key strategies to enhance your defences:

Robust Policies

Establishing and enforcing strict security policies and procedures is crucial. These policies should include:

  • Access Controls: Limiting access to sensitive information and systems based on the principle of least privilege.
  • Password Management: Enforcing strong password policies and regular password changes.
  • Data Classification: Categorising data based on its sensitivity and implementing appropriate handling procedures.

Multi-Factor Authentication (MFA)

Implementing Multi-Factor Authentication (MFA) adds an extra layer of security beyond just passwords. MFA can significantly reduce the risk of account compromise by requiring additional verification methods, such as:

  • One-Time Passwords (OTPs): OTPs sent to a user’s mobile device or email.
  • Biometric Verification: Using fingerprints, facial recognition, or voice authentication.
  • Hardware Tokens: Physical devices that generate a secure code required for login.

Training and Awareness

Regular training programs are essential to educate employees about the latest social engineering tactics and how to recognise them. Training should cover:

  • Phishing Simulations: Conducting regular simulated phishing attacks to test and improve employees’ ability to identify and respond to phishing attempts.
  • Incident Reporting: Implementing a policy and dedicated channel for reporting incidents, encouraging employees to report suspicious activities promptly can help mitigate the damage caused by a social engineering attack, or even prevent them from being successfully executed.
  • Role-Specific Training: Tailoring training to the specific roles and responsibilities of employees. For example, executives and finance staff may be targeted differently than IT personnel.

Regular Security Testing

Conducting regular phishing simulations and security audits helps identify and address vulnerabilities. These tests should include:

  • Red Team ExercisesSimulating real-world attack scenarios to test the effectiveness of your organisation’s people, processes and technology at identifying, detecting and responding to various threats.
  • Penetration TestingIdentifying and remediating vulnerabilities before they can be exploited by attackers.
  • Vulnerability AssessmentsContinuously scanning for and addressing potential security gaps in your systems.

Incident Response Planning

Having a well-defined incident response plan ensures that your organisation can quickly and effectively respond to social engineering attacks. Key components include:

  • Incident Response Team: Establishing a dedicated team to handle security incidents. Building and maintaining an in-house incident response team can be costly and resource intensive. Outsourcing to a dedicated team of incident response experts on retainer, such as Sophos, is a practical alternative to alleviate some of these cost and resource burdens associated with maintaining IR forensic expertise and capabilities in-house, and provides peace of mind that a competent team of experts is ready to respond to a security incident should one occur.
  • Communication Protocols: Outlining how to communicate internally and externally during a security incident. This should involve establishing clear guidelines for informing all relevant internal and external stakeholders, creating a crisis communications plan, and regular drills.
  • Post-Incident Reviews: Conducting a thorough analysis of the incident to identify lessons learned so that you can harden your organisation’s cyber security posture and mitigate future attacks.

Additional Recommended Resources:

By understanding the tactics used in social engineering and implementing these protective measures to counter them, organisations can significantly reduce their risk of falling victim to these deceptive attacks.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Securing Healthcare Organisations

Securing Healthcare Organisations with Modern Cyber Defence Strategies

Navigating Cyber Security Challenges

Healthcare organisations often face challenges in safeguarding sensitive patient data and critical infrastructure.

With 67% of healthcare organisations hit by ransomware last year, the threat level is high. In this blog, we explore the complexities of securing healthcare organisations amidst the evolving threat landscape and discuss strategies to mitigate risks effectively.


Understanding the Threat Landscape

Healthcare organisations are prime targets for cyber attacks due to the valuable information they possess, including medical records, financial data, and intellectual property. Threat actors, ranging from cyber criminals to nation-state actors, constantly probe for vulnerabilities to exploit.

Some of the most common threats to healthcare include:

  1. Phishing Attacks: Cyber criminals use deceptive emails or messages to trick employees into revealing sensitive information or installing malware.
  2. Ransomware: Malicious software encrypts critical data, rendering it inaccessible until a ransom is paid, disrupting healthcare operations and patient care.
  3. IoT Vulnerabilities: The abundance of Internet of Things (IoT) devices in healthcare introduces new attack vectors, posing risks to patient safety and data integrity.

Cyber Diagnosis: Navigating Cyber Security Challenges in Healthcare

In this exclusive webinar hosted by CyberLab, in collaboration with industry-leading partners Sophos, Logpoint, Forescout, and SecurEnvoy, we explore how to safeguard healthcare organisations against cyber threats.


“We have Microsoft E5 licences, are the included protections enough?”

Many healthcare organisations leverage Microsoft E5 licenses for cyber security capabilities. While these subscriptions offer robust security controls, they may not address all security requirements.

  1. Comprehensive Coverage: Assess whether E5 subscriptions adequately cover endpoints, servers, and other critical assets, including unmanaged IoT devices.
  2. Third-Party Integration: Evaluate the interoperability of Microsoft tools with third-party solutions to ensure comprehensive threat detection and response capabilities. For example, Sophos offer MDR for Microsoft Defender.
  3. Continuous Improvement: Cyber security is an ongoing process and organisations need to invest in regular assessments, updates, and training to stay ahead of emerging threats.


Balancing Budget Constraints and Cyber Security

Securing healthcare organisations requires striking a balance between budget constraints and cyber security needs. Key strategies include:

  1. Risk-Based Approach: Prioritise investments based on the organisation’s risk profile, focusing on critical assets and vulnerabilities.
  2. Baseline Security Practices: Implement foundational security measures, such as patch management, access controls, and employee training, to establish a strong security posture.
  3. Vendor Collaboration: Partner with trusted vendors and technology providers to leverage expertise, identify gaps, and implement cost-effective security solutions tailored to the organisation’s needs.


Next Steps

Securing healthcare organisations is a multifaceted challenge that demands a proactive and strategic approach. By understanding the evolving threat landscape, evaluating security controls, and balancing budget constraints with cyber security priorities, healthcare institutions can mitigate risks effectively and safeguard patient data, ensuring continuity of care.

CyberLab look after over 150 public and private healthcare providers, working together to develop solutions that secure their sensitive data, meet compliance requirements, and ensure online threats don’t compromise their operation.

Our range of security services and solutions have been developed to meet the requirements of the NHS Data Security and Protection Toolkit (DPST) and future-proofs against the NCSC’s Cyber Assessment Framework (CAF).

Want to know more about how to secure your healthcare organisation? CyberLab will be at the Healthcare Excellence Through Technology (HETT) Conference in London, so come and talk to us!

Find out more about our healthcare solutions or book a consultation to speak to one of our experts.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Top Five Cyber Incidents of 2024 New

Top 5 Cyber Attacks of 2024: Even The Mighty Can Fall in Minutes

Even the Mighty Can Fall: The Top Five Cyber Incidents of 2024 So Far

Ministry of Defence, Microsoft, and more!

As we approach the halfway point of 2024, we have already witnessed several significant cyber incidents that have had far-reaching impacts on major global organisations. These incidents have led to the likes of the MITRE, Microsoft and even the Ministry of Defence (MoD), having to answer uncomfortable questions as to how these incidents occurred.

In this blog, we highlight the top five cyber incidents of the year so far, examining what happened, who was affected, the fallout, and the broader implications for cyber security practices. Join us as we cover these major cyber incidents and explore the lessons we can learn from them.


Chinese State-Sponsored Cyber Attack Campaign

Hackers backed by China’s government spy agency have been accused by the US and UK of conducting a year-long cyber-attack campaign, targeting politicians, journalists, and businesses. The campaign, attributed to a Chinese state-sponsored hacking group, aimed to steal sensitive information, and disrupt critical infrastructure. These coordinated cyber attacks reveal the growing threat posed by nation-state actors and the need for international cooperation to combat hostile nation states or state backed cyber threats effectively. [source: The Guardian]

These attacks highlight that cyber threats don’t just originate from opportunistic cyber criminals, they also have the power of nation-states behind them. Organisations need to ensure they are regularly reviewing their cyber security posture to ensure that cyber defences are up to date and current best-practices are followed. A cyber security posture assessment can highlight the strengths of your organisation’s defences and also indicate where you should focus for improvement.


Ministry of Defence Data Breach

In a significant data breach reported earlier this month, personal information of an unknown number of serving and former UK military personnel was accessed through a payroll system used by the Ministry of Defence (MoD). The compromised data includes names, bank details, and, in some cases, personal addresses. The breach, which targeted a system managed by an external contractor, did not involve any operational MoD data. Immediate action was taken to take the system offline, and investigations are ongoing. Defence Secretary Grant Shapps is set to outline a response plan, which will include measures to protect affected individuals.

Whilst it has still not been revealed as to who is behind the attack, this incident highlights the importance of securing supply chains and systems managed by external contractors and demonstrates how easily vulnerable products can leave even the most mature organisations exposed to persistent threat actors.


MITRE R&D Network Penetrated

In another unfortunate tale of supply chain security, MITRE disclosed a significant cyber-attack in April 2024, orchestrated by state-sponsored hackers that exploited zero-day vulnerabilities in Ivanti VPN software.

MITRE are a key player in R&D for US government projects and authors of the widely adopted MITRE ATT&CK framework . The attack, attributed to a Chinese cyber espionage group known as UNC5221, targeted MITRE’s NERVE (Networked Experimentation, Research, and Virtualization Environment) an unclassified network used for research and development.

The hackers leveraged vulnerabilities CVE-2023-46805 and CVE-2024-21887, deploying sophisticated malware such as BrickStorm and BeeFlush, and used compromised administrator credentials to create rogue virtual machines.

This breach again underscores the critical importance of supply chain security, as vulnerabilities in third-party products can serve as entry points for significant cyber attacks. Organisations looking to prevent these types of attacks should have rigorous vulnerability management and ensure they are using supply chain risk assessments to determine the best third-parties to work with.

Despite maintaining persistence and attempting lateral movement within the NERVE infrastructure, the attackers failed to access other resources. This highlights the importance of architecture and configuration as although the hackers got in, their movement within the network was restricted and therefore reduced the damage these cyber criminals could do.


Microsoft Azure Data Breach

According to an article posted by Spiceworks, Microsoft’s premier cloud service, Azure, suffered a data breach in February 2024 affecting hundreds of executive Azure accounts, raising concerns over the security of big cloud-based platforms. The breach revealed critical vulnerabilities in Microsoft’s security measures, similar to previous incidents.

The attackers exploited a zero-day vulnerability, CVE-2024-21410, in Microsoft Exchange servers, which allowed them to access and misuse Windows NT Lan Manager (NTLM) hashes to impersonate legitimate users. Up to 97,000 Exchange servers are vulnerable to this flaw, which has a severity rating of 9.1. Additionally, Microsoft disclosed two more zero-day vulnerabilities: CVE-2024-21412, a security feature bypass, and CVE-2024-21351, a SmartScreen bypass vulnerability. These issues affected Exchange server versions before the February 13th update.

The perpetrators are believed to be hacking groups from Nigeria and Russia using proxy services and phishing links embedded in documents, primarily targeting mid and senior-level executives. This attack, involving user impersonation, data extraction, and financial fraud, marks the first time such a breach has occurred on the Azure platform.

Microsoft has since implemented measures to mitigate the impact of the breach and enhance the security of its cloud services. This incident brought Microsoft back under fresh scrutiny as a similar incident occurred in 2023 where Chinese-backed hackers were able to access sensitive data stored within the Azure platform [source: NPR]

These two incidents underscore the importance of regular vulnerability scanning and patch management. Organisations looking to mitigate risks from outdated software and zero-day vulnerabilities should ensure they have a robust patch management process and conduct regular vulnerability scans across their infrastructure and applications to maintain the integrity of their estate.

With such a vast and evolving suite of customisable products and features, it can be hard to stay up to date with the most recent security recommendations for Microsoft 365. In a Microsoft 365 Security Assessment, CyberLab can help you ensure security in your day-to-day operations by reviewing your MS365 configuration against industry-standard benchmarks from the Centre for Internet Security (CIS).


Cyber Attacks on NHS Dumfries and Galloway

Digital transformation has revolutionised processes and information management, especially within the healthcare sector. However, with these advancements come significant cyber security challenges.

NHS Dumfries and Galloway faced significant disruptions due to a cyber attack targeting its systems. The attack, which occurred in early 2024, prompted concerns over the security of sensitive healthcare data and patient records.

While details about the nature and extent of the breach remain limited, the incident underscores the persistent threat posed by cyber attacks on critical infrastructure, particularly in the healthcare sector.

Learn about the complexities of securing healthcare organisations amidst the evolving threat landscape and discover the strategies to mitigate risks in our Securing Healthcare Organisations blog.


In Conclusion

In conclusion, the top five cyber attacks of 2024 so far serve as a stark reminder of the evolving threat landscape. By understanding these incidents and implementing a layered and strategic approach to cyber security, organisations can better protect their people, data, and customers.

Stay vigilant, continuously update your defences, and ensure your incident response plans are robust to safeguard against future cyber threats.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Exploiting ChatGPT

Exploiting ChatGPT: The Darkside of AI and Emerging Cyber Threats

How Cyber Criminals Are Weaponising AI

Artificial intelligence (AI) being used for malicious intent has surfaced as a significant concern within the digital spaceCyber criminals are using Large Language Models (LLMs), like ChatGPT, and deepfake technology to launch cyber-attacks and scams. In this blog, we focus on the darker facets of AI, shedding light on the exploitation of AI systems, its impact on the threat landscape, and what organisations can do now to better protect themselves and their most sensitive assets against this new wave of threats. 

Malicious ChatGPT Prompts for Sale on the Dark Web Marketplace 

  • Recent reports reveal a disturbing trend where thousands of malicious prompts designed to jailbreak and exploit AI are up for sale on the dark web. These prompts deceive AI models, enabling threat actors to steal data, orchestrate sophisticated scams and other illegal activities with alarming efficiency. 
  • According to recent research carried out by Kaspersky, thousands of these nefarious prompts and compromised premium ChatGPT accounts are now available for purchase, posing a significant threat to ChatGPT, its users and their data. (source: The Register) 


Deepfake and AI: Partners in Crime

AI and deepfake technologies are becoming more readily available. OpenAI, for example, recently announced their new generative AI, Sora, that can create video from text. And, although this advancement in technology and its availability is exciting, it is also inevitable that there will be cyber criminals looking to use it maliciously. 

Around the globe we are already seeing examples of these technologies being exploited by advanced threat actors, including cyber criminals, nation states or nation sponsored hacker groups. 

$25 million theft executed through a sophisticated deepfake scam

A recent article by Ars Technica has shed light on a ground-breaking cyber crime incident considered to be the first successful heist of its kind: a $25 million theft executed through a sophisticated deepfake scam. The scam involved the creation of highly convincing AI generated deepfake videos, which were used to impersonate key individuals within a financial institution.  

By leveraging these deepfake videos, the scammer manipulated employees into authorising fraudulent transactions, resulting in the substantial loss. This unprecedented heist marks a significant escalation in the sophistication of cyber criminal tactics, underscoring the evolving threat landscape faced by organisations worldwide. As the prevalence of AI-driven scams will inevitably continue to rise, it becomes increasingly crucial for businesses to bolster their cyber security posture and remain vigilant against such deceptive schemes. 

Deepfake news segments 

Iran-backed hackers had recently disrupted TV streaming services in the United Arab Emirates (UAE) by injecting deepfake news segments into the broadcasts according to The Guardian. These deceptive deepfake videos, generated using AI technology, were designed to resemble legitimate news reports, spread misinformation, and sow discord among viewers. This incident underscores the growing threat posed by state-sponsored threat actors and the increasing weaponisation of deepfake technology for political purposes.  

As nations continue to grapple with the challenges of cyber warfare and disinformation campaigns, it becomes imperative for governments to collaborate and implement international legislation that both prohibits and protects against the use of such attack methods, as well as educate and inform organisations across all industries about AI threats and how best to protect themselves and their assets. Additionally, organisations need to enhance and adapt their cyber security capabilities to be able to identify and defend against orchestrated AI driven attacks, which is backed up by a recent assessment conducted by the NCSC. The assessment focuses on how AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years. (source: NCSC) 

Tales from the CyberLab: Generative AI in Cyber Security Explained


Global Cyber Threats Expected to Rise With AI, NCSC Warns

According to the above-mentioned assessment by the NCSC, AI is poised to significantly impact the cyber threat landscape in the near future. The report suggests that AI will almost certainly be utilised by cyber adversaries to enhance their capabilities, including the development of more advanced attack techniques and procedures (TTPs).  

As AI technologies evolve, cyber criminals are increasingly going to automate tasks, evade detection, and execute targeted attacks with greater precision. This assessment underscores the urgent need for organisations to adapt their cyber security strategies to effectively mitigate the evolving threats posed by AI-driven cyber-attacks. This includes enhancing detection and response capabilities, investing in AI-powered security solutions, enforcing zero trust policies, implementing a culture of sufficient cyber awareness and vigilance amongst staff, and staying informed about emerging AI-driven threat vectors. 

While ChatGPT and other LLMs may not yet be capable of being used to write sophisticated malware to be sold at scale on the dark web or be in possession of nefarious nation states, we may not be far away from AI being used to orchestrate attack chains or write malware that can evade detection. A separate recent report from the National Cyber Security Centre (NCSC) sheds light on how AI driven ransomware attacks could become a reality by 2025. (source: NCSC)


What Can Organisations do to Protect Themselves Against AI Threats?

As AI technologies are rapidly evolving, the application of its use for both good and bad is evolving with it, leading to a rapid shift in the threat landscape. It is imperative for organisations to not just understand how to defend against AI driven threats, but to learn how to use AI technologies securely and in a manner that best protects their assets and does not expose them to new vulnerabilities or risk. 

Already we are seeing collaboration amongst the international community to tackle this very issue. A recent publication on how to engage with Artificial Intelligence has been developed by the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in collaboration with the NCSC, United States (US) Cyber security and Infrastructure Security Agency (CISA), Canadian Centre for Cyber Security (CCCS) and several other cyber security/government agencies from international partners. The publication highlights some key threats related to AI systems and summarises steps organisations should take when engaging with AI technologies (both in-house and 3rd parties) to mitigate risk. (source: ASD’s ACSC) 

While this new wave of advanced threats seems daunting and paints a bleak future for stakeholders responsible for managing risk, there are several steps organisations can do to protect against these threats. Many of these types of attacks still rely on the presence of human error and social engineering. Regularly training your people and creating a positive cyber awareness culture are key to reducing this type of threat.

Further to this, unsecured vulnerabilities are a common route of entry for cyber criminals and can be identified with regular vulnerability scanning and penetration testing to identify your security weak spots.

Organisations across all sectors, of all sizes should not neglect the fundamental steps that make up the foundations of any cyber security strategy. Few organisations have the right tools, people, and processes in-house to manage their security program around-the-clock while proactively defending against new and emerging threats. Adopting security defences like Sophos MDR can provide an elite team of threat hunters and response experts to take targeted actions on your behalf to neutralise even the most sophisticated threats.

Tales from the CyberLab: AI’s Role in Data Protection Explained


In Conclusion

For better or worse, AI is going to change how we live our lives greatly, and while its application for solving huge problems on a global scale is something to be embraced, we should also be aware of its capacity to cause great harm. Organisations need to adapt to the new world of AI driven technologies and attacks, whilst continuing to invest in the foundations of their cyber security posture.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Mobile Security Threats

Mobile Security Threats & How To Protect Yourself from Common Risks

Your 2025 Guide to Mobile Threats and Defences

Adam Myers, Sales Director at CyberLab, outlines the evolving mobile threat landscape and offers actionable advice to help organisations and individuals secure their mobile devices.

Mobile devices are now central to business operations. According to Microsoft, over 80% of daily work is conducted on mobile platforms. These devices operate outside traditional corporate firewalls and are often in the hands of users who may not prioritise security – making them prime targets for cyber criminals.


Why Mobile Security Matters More Than Ever

Employees routinely access emails, documents, customer data, and applications via mobile devices. While this boosts productivity, it also increases exposure to threats such as malware, phishing, and data breaches.

The rise of Bring Your Own Device (BYOD) policies and remote work has further complicated mobile security management.


Top Mobile Security Threats in 2025

1. Outdated Operating Systems and Security Patches

Devices typically stop receiving updates within 3–4 years of release. Unpatched vulnerabilities are a leading cause of mobile breaches. Microsoft’s Secure Future Initiative urges organisations to retire outdated systems before they become liabilities.

2. Unsecured Third-Party Apps

Apps downloaded outside official stores (e.g. sideloaded APKs on Android) can introduce malware. These apps may access sensitive data, including passwords and banking details, without user awareness.

3. Weak Passcodes

Simple passcodes like “1234” or birthdates are easily guessed. Best practice now recommends 8-digit passcodes with no repeating patterns. Biometric authentication and phishing-resistant MFA are also strongly advised.

4. Unsecured Wi-Fi Networks

Public Wi-Fi remains a major risk. Attackers can intercept unencrypted traffic or hijack sessions. Microsoft recommends avoiding public networks unless using a trusted VPN.

5. BYOD Risks

Personal devices used for work can introduce threats if not properly managed. Risks include data theft, unauthorised app downloads, and lack of visibility into device security posture.

6. Lack of Endpoint Protection

Endpoint protection is no longer optional. Sophos and Microsoft now offer AI-powered threat detection and response for mobile endpoints, including behavioural analysis and automated containment. [microsoft.com]

7. Device Loss or Theft

EE reports that 10 million work devices are lost annually. Mobile Device Management (MDM) solutions allow remote wiping, location tracking, and access revocation to mitigate this risk.

8. Human Error

Employees remain a top vulnerability. Regular training and phishing simulations are essential. CyberLab’s layered security approach includes education, monitoring, and proactive threat hunting.


Mobile Device Management (MDM): Your First Line of Defence

An MDM solution helps organisations:

  • Remotely wipe or lock lost devices
  • Enforce strong passcode policies
  • Ensure OS updates are applied
  • Restrict access to risky apps
  • Manage BYOD securely

MDM is cost-effective, easy to deploy, and scalable. CyberLab offers tailored MDM solutions—from entry-level setups to enterprise-grade deployments—based on your business needs.

Tales from the CyberLab: Cyber Security for Websites & Applications Explained


CyberLab Can Help

Speak with a CyberLab expert to review your mobile security posture and explore solutions tailored to your organisation. Book your free 30-minute consultation today.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

CyberLab Working

Five Essential Cyber Security Measures: Practical Cyber Security Tips

Practical Cyber Security Tips Every Small Business Should Know

With the increasing frequency and sophistication of cyber attacks, it is crucial for SMEs to adopt robust cyber security practices to safeguard their business and data.

This blog focuses on essential cyber security best practices tailored for SMEs, highlighting key resources and actionable steps to protect your business.


Cyber Security Best Practices for SMEs

Implementing effective cyber security measures doesn’t require a massive budget or extensive expertise.

Employee Training and Awareness

Educate your staff about common cyber threats such as phishing, malware, and social engineering. Regular training sessions can help employees recognise and avoid potential security risks.

Strong Password Policies

Encourage the use of strong, unique passwords for all accounts. Implement multi-factor authentication (MFA) wherever possible to add an extra layer of security.
Regular Software Updates: Keep all software, including operating systems and applications, up to date with the latest security patches. Regular updates help protect against known vulnerabilities.

Data Encryption

Encrypt sensitive data both in transit and at rest. This ensures that even if data is intercepted or accessed without authorisation, it remains unreadable.

Backup and Recovery Plans

Regularly back up your data and ensure that backups are stored securely. Test your recovery plan to ensure that you can quickly restore operations in the event of a cyber incident.

Gain Cyber Essentials

Achieving Cyber Essentials certification demonstrates your commitment to cyber security and provides a solid foundation for your security practices.


Understanding Cyber Essentials

Cyber Essentials is a UK government-backed certification scheme led by IASME, designed to help organisations of all sizes protect against common online threats.

The scheme covers five key areas:

  • Firewalls and Internet Gateways: Implementing firewalls to secure your internet connection.
  • Secure Configuration: Ensuring that systems are configured securely to reduce vulnerabilities.
  • Access Control: Managing user access to data and services to minimise risk.
  • Malware Protection: Installing and maintaining anti-malware solutions.
  • Patch Management: Keeping software up to date with the latest security patches.

By adhering to these principles, SMEs can significantly reduce their risk of cyber attacks and improve their overall security posture.

Get Cyber Essentials

Actionable Steps for SMEs

Here are additional steps small businesses can take to protect themselves from cyber threats.

Conduct Regular Security Audits

Periodically review your organisation’s security posture, taking a holistic approach that assesses to identify and address any vulnerabilities or gaps. There are several, open-source industry standards and security frameworks available online that organisations, including SMEs, can align to such as NISTCIS Critical Security Controls SME Companion, and NCSC. CIS even offers a free Controls Self-Assessment Tool (CIS CSAT) to help you get started.

Vulnerability Management

Regularly identify, assess, and mitigate vulnerabilities in your systems. Using Cyber Security as a Service (CSaaS) solutions, such as HackRisk, can help you stay on top of vulnerabilities without the need for a dedicated in-house team

Develop an Incident Response Plan

Prepare for potential security incidents by creating a response plan. Outline procedures for detecting, responding to, and recovering from cyber-attacks. Sophos offers a free incident response planning guide which can be downloaded here.

Utilise Cloud Security Solutions

Many cloud service providers offer robust security features that can help SMEs protect their data and applications.

Outsource to Experts

If maintaining an in-house cyber security team is not feasible, consider outsourcing to a dedicated team of experts. Services such as those offered by Sophos provide ongoing support and incident response capabilities, alleviating some of the cost and resource burdens.

Communication Protocols

Establish clear protocols for communicating internally and externally during a security incident. This ensures that information is disseminated quickly and accurately, minimising confusion and mitigating damage.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Access and ID Management

Identity and Access Management: Controlling Access in a Digital World

Controlling Access in a Digital World: Why IAM Matters More Than Ever

Identity and Access Management, often shortened to just IAM, is the practise of ensuring that identity of who and what is accessing your environment is under control – that is, you have systems and, by association, data that can only be accessed by users and devices that you have authorised.

But it’s a lot more than just that, in any organisation people come and go, it is also about making sure that when users (or devices) should no longer be authorised to access your systems that they are not still able to do so.

It sounds simple, but in a busy organisation it is easy for simply disabling a user account to be forgotten. Removing access for users or devices is a vitally important step in any cyber security strategy, especially under unfortunate circumstances when people leave a business on bad terms.

Identity and Access Management is a crucial aspect of cyber security. It involves controlling who and what can access your systems and data. Access to data, systems, and services need to be protected. Understanding who or what needs access, and under what conditions, is just as important as knowing who needs to be kept out.


Why do we need Identity and Access Management?

Data is the lifeblood of any business; in any digital organisation today it is a critical component in maintaining business as usual operation, theft, access denial or destruction of data is not only disruptive, but without good backups it can be devastating at scale.

The next step is controlling access to the data. Any organisation will have sensitive data, and that data is sensitive for a reason, it would likely be detrimental to the business if lost or released publicly. Ensuring the data is only accessible to parties that are trusted and need to access the sensitive data is another essential part of Identity and Access Management.

Implementing Identity and Access Management

Which brings us to the how. In modern IT the term identity encompasses much more than just the user account in active directory, there can be multiple associated devices the instantaneous status of which can be leveraged to provide additional security. For example, you could consider whether a device is managed by the organisation? What is the patch status of a laptop? Is the mobile device jail-broken or rooted?

The steps below are suggestions on things that can be done, they are by no means exhaustive and not every step is applicable or appropriate for every organisation; but by implementing these elements you can have confidence that you are doing IAM right:

Identity and Access Management Policies

Organisations should look to develop appropriate IAM policies and processes.

  • Control who and what can access your systems and data. A good IAM policy that covers who should have access to which systems, data or functionality, why, and under what circumstances.
  • Consider all potential types of user including full and part-time staff, contractors, volunteers, students, and visitors.
  • Ensure the policy covers what and how audit records are acquired, and how they are safeguarded against tampering, and an identification of which actions or processes, if any, should require more than one person to perform or authorise them.
  • Policies should not just cover systems you control, but also wherever your organisational identities can be used – for example, consider the websites or online services that staff can create an account by using their work email address.

Login Methods

Establish and prove the identity of users, devices, or systems, with enough confidence to make access control decisions. Single sign-on (SSO) may be available using your organisational identity for some online services to help you control access to those services (and revoke access along with someone’s work account when they leave your organisation).

New Starters, Movers and Leavers

Ensure your account management processes include a ‘joiners, movers and leavers’ policy, so access can be revoked when no longer needed, or changed for movers. Temporary accounts should also be removed or suspended when no longer required.


In Conclusion

By following these steps, you can ensure that only individuals and systems that are authorised to have access to data or services are allowed to do so. This will result in less impact on staff’s workday by getting IAM right across an organisation, smoother collaboration with customers, suppliers, and partners.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

How To Prevent Cyber Attacks with Logging & Monitoring

How to Prevent Cyber Attacks with Effective Logging and Monitoring

Detecting and Preventing Cyber Incidents

Our host at explores how logging and monitoring can help your organisation detect cyber threats and secure your digital landscape.
They cover:
  • Why Do We Need Logging and Monitoring?
  • How Do We Do Logging and Monitoring?
  • Identifying the Right Solution
  • Our Recommendations

Cyber security is a big concern for businesses today. Over the past year alone, nearly half a million businesses reported cyber incidents. As our workplaces and digital systems grow, so does the chance of cyberattacks. These attacks are getting smarter, and as a result, the risk of being targeted is increasing.


Why Do We Need Logging & Monitoring?

With the advancements in technology and the move to hybrid working, our environments and workforces have moved more online. A consequence of this is that our organisations have a much larger attack surface for cyber criminals to try and exploit. Necessary interfaces between different on-premise and cloud or SaaS platforms mean environments are more complex to manage. Cyber attacks themselves are becoming more advanced and as a result, the likelihood of being attacked increases as well.

The dark web has been hugely commoditised and it is now very likely that multiple cyber criminals will gain awareness that you are vulnerable. This happens when one attacker, called an access broker, gains access to your environment and then sells that access to multiple other attackers. Their goal? Making money, causing chaos, stealing secrets, and holding your data hostage.

The risk and cost for organisations that are victim to cyber attacks are also increasing. The result of cyber attacks are often downtime, disruption and data loss. There are also other consequences many organisations face such damage to reputation, hefty fines for compromised data, losing trust from valued customers, and even the loss of hard-earned certifications.

While it might seem like a digital doomsday out there, here’s the secret: cyber attacks leave footprints. The art of prevention lies in spotting these traces before the attack compromises your systems and data. It’s like catching a thief in the act before they can make off with the loot. If you can detect unauthorised activity before damage is done, you can stop or prevent the attack being successful and limit the damage. That’s where logging and monitoring solutions come in.

They have a secondary function as well, anyone who has suffered a cyber attack will tell you that despite having the initial detection of something untoward going on, it can be really difficult to actually feel confidence that you can see the whole picture and you are aware of everything that’s going on – logging and monitoring helps with that as well.

How Do You Do Logging & Monitoring?

In even relatively small IT environments, the scale of log information that will be generated is overwhelming. Especially if it’s scattered across multiple environments like public/private cloud/SaaS etc.

The first challenge? Gathering all these pieces into a single, meaningful picture. Endpoint Detection & Response and eXtended Detection and Response (EDR/XDR) and Security Information and Event Management (SIEM) solutions provide this central location to collate and view the log information from multiple sources.

So, you’ve got all your puzzle pieces in one place, but they’re still just random bits until you put them together. That’s where the real magic happens: processing. EDR/XDR and SIEM solutions typically sift through the sea of data to block out the ‘noise’.

Solutions such as LogPoint leverage some form of AI or ML intelligence to give an indication of how likely a particular event is going to be related to malicious activity. LogPoint’s version is called UEBA, which stands for User Entity Behaviour Analytics. UEBA uses AI and ML to correlate multiple events and link related ones together to give a fuller picture than looking at individual events in isolation.

EDR/XDR solutions usually do something similar but typically the events they are correlating are limited to information coming from endpoint security or proprietary network devices. LogPoint and other SIEM tend to have a much broader scope of interoperability and call pull event information from pretty much anywhere that it’s being generated.


How Do I Know Which Solution Is Right?

It can be difficult to know which solution is right for your organisation, and its often a case of selecting which fulfils your need the best. If you don’t need to monitor extensive hardware devices, web sites, databases, etc, then an EDR/XDR solution might be for you. If you have multiple databases or databases that hold sensitive information, it’s probably a good idea to be watching them closely via a SIEM solution as they will be a prime target for an attacker.

With both types of solution the information still needs to be monitored by a human. LogPoint mitigate this through the use of their Security Orchestration and Response (SOAR) technology that aims to take automated action based on certain triggers when particular activity is detected. EDR/XDR solutions often have similar functionality but it’s probably fair to say they are not quite as extensive or complex as a SIEM solutions.

These automated response solutions are great, but they can also be incredibly disruptive if allowed free reign over systems. Very quickly users will be complaining they cannot carry out their duties because things are being blocked. This brings me to the final challenge with logging and monitoring, it invariably means a security specialist with “eyes-on-glass” (i.e., watching the screen) is necessary to manage both types of solutions effectively.

Again, the approach to take to manage this final challenge depends on any number of factors – the size of business, the driving forces behind the adoption of logging and monitoring, the desire for Opex over Capex, or the constant problem of getting skilled Cyber security staff, to name just a few.

What Would CyberLab Recommend?

If an organisation lacks in-house expertise but recognises the value and importance of logging and monitoring, it is increasingly common to adopt a managed service approach.

This involves partnering with third-party suppliers who have dedicated security specialist teams to handle the heavy lifting. One of the key benefits of this approach is peace of mind – knowing that systems are being actively protected around the clock.

To support this, the Posture Assessment tool offers a quick and easy way to identify strengths and weaknesses, providing a clearer picture of overall security posture.

A dedicated page of recommendations for improving logging and monitoring is available, including guidance on which tools can help.

For organisations looking to strengthen their security and protect their data, a consultation with one of our experts is available to explore tailored solutions.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Vulnerability Management Cyber Security

Vulnerability Management for Stronger Cyber Security Resilience

Protect Your Data. Secure Your Organisation.

Our host discusses the key elements of vulnerability management and shares how to protect your organisation through robust practices and monitoring.

He covers:

  • What is vulnerability management?
  • Why do we need vulnerability management?
  • Key steps to vulnerability management


What is Vulnerability Management?

Vulnerability management is the process of identifying and addressing weaknesses in computer systems, networks, and software that could be exploited by hackers or cause security breaches.

It involves regularly scanning and assessing these systems to discover any vulnerabilities or potential entry points for attacks.

Once identified, these vulnerabilities are prioritised based on their severity, and appropriate measures are taken to fix or mitigate them.

Why Do We Need Vulnerability Management?

By actively managing vulnerabilities, organisations can reduce the risk of cyber attacks and safeguard their sensitive information from unauthorised access or damage.

Software Updates

Software might be fine at the time it is released, but as time and requirements move on, the code of the software does too. This could be to add cool new features or to add a flashy new interface, but it’s becoming more important to fix security issues or vulnerabilities. These issues can be found either by security testers known as ‘Bug bounty’ hunters or the software vendor themselves.

Fixing these vulnerabilities prevents cyber-attacks from exploiting them. According to a recent report by the Ponemon Institute, more than half (57%) of reported data breaches could have been avoided if known vulnerabilities had been patched correctly.

What are the Risks of Not Updating?

Keeping outdated software can be a big risk for an organisation – it’s like leaving your door unlocked. A study by the Centre for Strategic and International Studies revealed that cybercrime costs the global economy more than $1 trillion each year, with a significant portion resulting from data breaches.

The rising cost of cyber insurance is another risk that organisations need to consider. Companies that neglect proper vulnerability management practices often face higher cyber insurance premiums, Cyberpolicy estimates that companies without basic patch management measures in place may face cyber insurance premiums up to 25% higher.


Key Steps to Vulnerability Management

Gain Visibility

Scanning internally and externally with vulnerability assessment tools can highlight network layer “low hanging fruit” vulnerabilities that hackers will be looking to find the quickest and or least detectable entry point into an organisation’s network. According to a study by Spiceworks, 72% of IT professionals use vulnerability scanning tools to identify and remediate security risks.

Identify Risk

To effectively manage vulnerabilities, you need to identify and eliminate areas of risk, such as unsupported operating systems, hardware, and applications. Essentially, anything connected to your internal infrastructure and external interfaces adds to this risk. According to a report by Tripwire, 76% of respondents identified legacy systems as the main challenge to their security.

Secure Your Websites

Knowing which web applications are accessible to the public via web browsers is crucial for your cybersecurity strategy. Protecting externally facing web applications that hold sensitive data (such as PII, PHI, PCI data, or commercially sensitive/customer data) is vital.

Performing regular vulnerability scans and at least one manual penetration test per year helps organisations address new vulnerabilities. It also helps to prevent unauthorised access to sensitive data, compromised user accounts, or external threats with increased privileges that could cause further harm.

Protect Your Data

In today’s world, attackers primarily target your data. They aim to either steal it, deny you access to it, or both, with the goal of extorting money from your organisation.

When you consider how your data can be accessed, you can identify potential sources of risk and develop a strategy to minimise those risks. This involves considering vulnerabilities and controls, such as limiting access to authorised individuals, to protect your data effectively.

Addressing Your Vulnerabilities

It may seem obvious, but patch management is often overlooked or delayed, leading to future problems. Investing in reliable and effective automated patch management solutions is the best approach. While they may cost more, they require less constant tweaking and management, giving you confidence in their effective patching.

Identifying problems is often straightforward, but finding solutions can be challenging, especially when dealing with legacy or unsupported mission-critical operating systems or applications that cannot be shut down.

Scheduled downtime is crucial to apply security fixes to these systems. If they are attacked without fixes in place, you’ll face unscheduled downtime, which is worse. If downtime or security fixes are not feasible, alternative solutions like Forescout can be used to implement effective network access controls and restrict access to vulnerable areas only to authorised entities.

Utilise Reporting

Managing vulnerabilities at a large scale is impractical as it would require constant effort to find and fix issues. Automation is the key to making it feasible. Reporting can be used to identify existing issues before applying patches and to verify the effectiveness of the patching process. Most solutions offer automated reports that range from high-level summaries to detailed breakdowns of vulnerabilities.


How CyberLab Can Help

CyberLab can provide consultancy and support on your key technology projects, help deliver business solutions, support your users in adopting them and provide managed or reactive support when your solution is up and running.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

The Top Five Cyber Threats of 2024

The Top Five Cyber Threats of 2024 and How to Strengthen Resilience

Mid-Year Analysis on Cyber Security Trends for 2024

As we progress through 2024, the cyber threat landscape continues to evolve rapidly, presenting new challenges for organisations and individuals alike. In this edition, we shift our focus from past incidents to the present and future threats that pose the greatest risks.

Understanding these threats is crucial for developing effective strategies to safeguard against them. Cybercrime is expected to become the world’s third largest economy by 2025, estimated to cost $10.5 trillion in damages globally, according to cybercrime magazine.

This month, we highlight the top five most dangerous cyber threats of 2024, exploring their nature, potential impacts, and the steps you can take to protect yourself and your organisation. Join us as we explore these pressing cyber threats and provide insights into enhancing your cyber resilience.


Offensive AI as a Threat Multiplier

At the RSA Conference 2024, cyber security experts identified offensive AI as a significant threat multiplier, presenting it as one of the top five cyber threats for the year. Stephen Sims highlighted how malicious actors leverage AI and automation to rapidly identify vulnerabilities, automate the generation of exploits, and launch sophisticated attack campaigns.

This offensive AI capability accelerates the discovery and exploitation of vulnerabilities, posing a formidable challenge for defenders. Sims emphasised the urgent need for defensive strategies capable of countering the speed, automation, and intelligence wielded by attackers, underscoring the importance of innovative defensive measures to mitigate this evolving threat landscape in 2024.

AI-Driven Social Engineering Threats

Social engineering has long been a prominent cyber threat, relying on psychological manipulation to deceive victims. Attackers exploit human traits such as trust, fear, and curiosity to gain access to critical systems or sensitive information. Traditional social engineering methods include phishing, baiting, pretexting, and tailgating.

The increasing digital transformation and real-time information sharing have made individuals more susceptible to these attacks. In 2022 alone, there were 493 million ransomware attacks, and 19% of all data breaches were due to stolen or compromised login credentials.

AI has significantly amplified social engineering tactics, enabling attackers to develop more complex and convincing attacks tailored to targeted individuals. AI-driven social engineering can include:

  • Hyper-personalised phishing
  • AI-generated natural language content
  • Emotional manipulation
  • Detection evasion
  • Automated reconnaissance

These advancements allow attackers to craft tailored, context-aware campaigns quickly and efficiently, making traditional defences less effective. Businesses must now contend with AI-generated deepfakes, persuasive phishing emails, and sophisticated data manipulation, requiring a proactive and adaptive approach to cybersecurity.

Implementing multi-factor authentication, employee training, phishing simulations, and AI-based defence mechanisms are essential to counter these advanced threats.


Ransomware Remains a Prevalent Threat in 2024

Despite significant global law enforcement efforts, ransomware activity has continued to surge in 2024. According to the Sophos 2024 Ransomware Report, global ransomware attacks in 2023 set a record high, surpassing the previous year by nearly 70%. In the first quarter of 2024 alone, 1,075 ransomware victims were posted on leak sites. Major ransomware groups like LockBit and ALPHV/BlackCat were responsible for 30% of the activity.

The report also highlights the financial impact of these attacks, with average ransom payments increasing by 500% in the last year. A staggering 63% of ransom demands were for $1 million or more, and 30% exceeded $5 million, indicating that ransomware operators are targeting larger payoffs.

Overall, these reports indicate that ransomware isn’t slowing down in 2024 and remains one of the largest threats to organisations. Few organisations have the right tools, people, and processes in-house to manage their security program around-the-clock while proactively defending against new and emerging threats.

Supply Chain Risk: A Growing Concern

Supply chain risk continues to be a significant threat in 2024, as we’ve already seen from major incidents this year involving MoD and MITRE, which we covered in our blog outlining the top five cyber incidents of 2024 so far. Despite increased awareness, many businesses still struggle with effectively managing these risks. According to the UK Government’s Cyber Security Breaches Survey 2024, 31% of businesses and 26% of charities conducted cyber security risk assessments in the past year. Larger organisations are more proactive, with 63% of medium businesses and 72% of large businesses conducting these assessments.

However, only 11% of businesses review the cyber risks posed by their immediate suppliers, a figure that rises to 28% for medium businesses and 48% for large businesses. This limited oversight is concerning given the complex and interconnected nature of modern supply chains. The qualitative data indicates that while awareness of supply chain cybersecurity risks is growing, smaller organisations often lack the formal procedures necessary to manage these risks effectively.


Cloud Vulnerabilities: The Invisible Threat

As organisations continue to migrate their operations to the cloud, vulnerabilities within cloud environments have become a critical concern in 2024. The flexibility and scalability of cloud services come with a unique set of security challenges that can be exploited by well-versed threat actors.

A significant factor contributing to cloud vulnerabilities is misconfiguration. According to reports as far back as 2019, misconfigured cloud settings were responsible for nearly 70% of all cloud security incidents, and according to IBM’s Cost of a Data Breach Report, 45% of reported breaches were cloud-based. These misconfigurations can lead to unauthorised access, data leaks, and compliance issues. Additionally, the shared responsibility model of cloud security often leads to confusion about where the provider’s security obligations end and the client’s responsibilities begin, leaving gaps that can be exploited. The NCSC has published free guidance on cloud security and shared responsibility models.

The rise in cloud-based attacks has also been driven by increasingly sophisticated threat actors targeting cloud infrastructure. For instance, the recent breaches involving high-profile cloud services such as the recent Microsoft Azure incident have shown that attackers are leveraging advanced techniques and exploiting zero-day vulnerabilities to bypass security controls, escalate privileges, and access sensitive data. These incidents highlight the importance of robust security practices, including regular audits, comprehensive monitoring, and strict access controls.

To mitigate cloud vulnerabilities, organisations should focus on improving their cloud security posture through continuous monitoring to identify any vulnerabilities or misconfigurations exposing their cloud infrastructure’s attack surface, employee training and implementing robust policies for access, user groups and data handling, and of course, adherence to best practices for cloud configuration and management. The Center for Internet Security (CIS) has published the CIS Benchmarks, a series of prescriptive recommendations for configuring over 25 cloud and network vendor product families including AWS, Azure and Google Cloud Platform (GCP).

By addressing these vulnerabilities proactively and implementing industry best practices and benchmarks, businesses can better protect their data and maintain trust with their customers.


What Can We Learn From These Trends?

The top five cyber threats of 2024 so far serve as a stark reminder of the evolving threat landscape. By understanding the risk and implementing a layered and strategic approach to cyber security, organisations can better protect their people, data, and customers.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation