Originally Posted Jan 21, 2022 by Chuck Brooks
The past two years has seen a rapid shift of work to remote and hybrid offices. The statistics show that hackers welcomed that shift and took advantage of the vulnerabilities and gaps in security by businesses.
Cyber risks top worldwide business concerns in 2022 Cyber risks top worldwide business concerns in 2022 - Help Net Security
“Cyber perils are the biggest concern for companies globally in 2022, according to the Allianz Risk Barometer. The threat of ransomware attacks, data breaches or major IT outages worries companies even more than business and supply chain disruption, natural disasters or the COVID-19 pandemic, all of which have heavily affected firms in the past year.
Cyber incidents tops the Allianz Risk Barometer for only the second time in the survey’s history (44% of responses), Business interruption drops to a close second (42%) and Natural catastrophes ranks third (25%), up from sixth in 2021. Climate change climbs to its highest-ever ranking of sixth (17%, up from ninth), while Pandemic outbreak drops to fourth (22%).y affected firms in the past year. “
Cybercriminals can penetrate 93 percent of company networks Cybercriminals can penetrate 93 percent of company networks (betanews.com)
“among the findings of a new study of pentesting projects from Positive Technologies, conducted among financial organizations, fuel and energy organizations, government bodies, industrial businesses, IT companies and other sectors. In 93 percent of cases, an external attacker can breach an organization's network perimeter and gain access to local network resources.”
Businesses Suffered 50% More Cyberattack Attempts per Week in 2021 Businesses Suffered 50% More Cyberattack Attempts per Week in 2021 (darkreading.com)
The rise — partly due to Log4j — helped boost cyberattack attempts to an all-time high in Q4 2021, new data shows. The education/research sector sustained the most attacks in 2021, followed by government/military and communications. Source: Check Point Software
Corporate Cyber Attacks Up 50% Last Year Corporate Cyber Attacks Up 50% Last Year (cybersecurityintelligence.com)
2021 saw 50% more cyber attacks per week on corporate networks compared to 2020.
Most Targeted Sectors Worldwide by Hackers in 2021
Cybersecurity and Small and Medium Sized Businesses
While many large businesses suffered breaches, small and medium businesses were an easier target for hackers because of their lack of resources and security expertise.
2022 Must-Know Cyber Attack Statistics and Trends 2021 Must-Know Cyber Attack Statistics and Trends - Embroker
Cyber attacks on all businesses, but particularly small to medium sized businesses, are becoming more frequent, targeted, and complex. According to Accenture’s Cost of Cybercrime Study, 43% of cyber attacks are aimed at small businesses, but only 14% are prepared to defend themselves.
Not only does a cyber attack disrupt normal operations, but it may cause damage to important IT assets and infrastructure that can be impossible to recover from without the budget or resources to do so.
Small businesses struggling to defend themselves because of this. According to Ponemon Institute’s State of Cybersecurity Report, small to medium sized business around the globe report recent experiences with cyber attacks:
The most common types of attacks on small businesses include:
10 Small Business Cyber Security Statistics That You Should Know – And How To Improve Them 10 Small Business Cyber Security Statistics That You Should Know – And How To Improve Them - Cybersecurity Magazine (cybersecurity-magazine.com)
“Keeping up with the latest cyber-attack statistics is pertinent for understanding the state of cyber threats, commonly leveraged vulnerabilities, implications of successful cyber attacks, and effective strategies for mitigating prevalent threats.
Most hospitals and healthcare facilities have traditionally focused their budgets on acquiring new medical technologies and improving patient care. Covid19 put a huge burden on budgets and hackers have exploited cyber vulnerabilities, especially via ransomware.
Healthcare Cybersecurity Report 2021-2022 Healthcare Cybersecurity Report 2021-2022 (herjavecgroup.com)
“70% of recently surveyed organizations reported that healthcare ransomware attacks have resulted in longer lengths of stays in hospital and delays in procedures and tests that have resulted in poor outcomes including an increase in patient mortality.”
Half of internet-connected devices in hospitals are vulnerable to hacks, report finds Half of internet-connected devices in hospitals are vulnerable to hacks, report finds - The Verge
“Over half of internet-connected devices used in hospitals have a vulnerability that could put patient safety, confidential data, or the usability of a device at risk, according to a new report from the healthcare cybersecurity company Cynerio.
The report analyzed data from over 10 million devices at over 300 hospitals and health care facilities globally, which the company collected through connectors attached to the devices as part of its security platform.”
With everything and anything connected, hackers can take advantage of many attack vectors and weak device passwords. The threat is growing as IoT expands.
Top 10 cyber security threats in 2021 List secondary lists page (cybermagazine.com)
According to Symantec, IoT devices experience an average 5,200 attacks per month. The fact that a majority of new IoT devices are still in their infancy means there is a much larger attack surface for cybercriminals to target the vulnerabilities associated with them.
For a deep dive on the IoT Cybersecurity conundrum, Please see my slide below and FORBES article: Cybersecurity Threats: The Daunting Challenge of Securing the Internet Of Things: Cybersecurity Threats: The Daunting Challenge Of Securing The Internet Of Things (forbes.com)
Although ransomware has been around for decades, in 2021 it became a preferred cyber-weapon of choice for hackers. Being able to exfiltrate and hold hostage data for payment of cryptocurrencies has made the deployment of ransomware a growing trend.
Ransomware Statistics, Trends and Facts for 2022 and Beyond Ransomware Statistics, Trends and Facts for 2022 and Beyond (cloudwards.net)
5 Key Ransomware Statistics:
Please also see my recent FORBES article:
Ransomware on a Rampage; a New Wake-Up Call Ransomware on a Rampage; a New Wake-Up Call (forbes.com)
“The sobering reality is that ransomware is on a rampage. Ransomware will continue to be a destructive threat because there are so many available soft targets. We live in an increasingly hyper-connected world that impacts all aspects of our lives. From now and onward, managing and protecting data will be a security imperative for every industry and organization.
Awareness and understanding the ransomware threat can help address many of the cybersecurity challenges. Emerging cybersecurity technologies, mitigation tools, and protocols can help limit the exploding trend of ransomware attacks. Taking pro-active measures to protect systems, networks, and devices, and be more resilient, need to be part of a new wake-up call.”
If you seek a more comprehensive overview of cybersecurity stats, please check out these compendium articles. They cover many policy, operational, and industry specific elements of the cybersecurity ecosystem.
CRYPTOCRIME
CYBERSECURITY SPENDING
VENTURE CAPITAL
Cybersecurity Ventures Infographic:
All the Cybersecurity Statistics, Figures and Facts You Need to Know in 2022
“State Sponsored Threats: According to Microsoft, nearly 80% of nation-state attackers targeted government agencies, thinks tanks and other non-government organizations.
The United States remains the most highly targeted country with 46% of global cyberattacks being directed towards Americans
Cost of Cybercrime rising: The cost of cyber crime has risen 10% in the past year.
Cybersecurity Workforce: it’s estimated that there will be 3.5 million unfilled cybersecurity jobs by the end of 2025.
The pandemic presented lots of new cybersecurity issues and companies are working diligently to ensure they are prepared for anything that comes their way in the future. Expect to see the following.
22 Cyberstatistics to Know for 2022
Phishing Attacks: Phishing attacks were connected to 36% of breaches, an increase of 11%, which in part could be attributed to the COVID-19 pandemic. As might have been expected, threat actors have been observed tweaking their phishing campaigns based on what’s making the news at any moment in time. (Verizon 2021 Data Breach Investigations Report)
Cost of Data Breach: 2021 saw the highest average cost of a data breach in 17 years, with the cost rising from US$3.86 million to US$4.24 million on an annual basis. (IBM Cost of a Data Breach Report 2021)
Ransomware Payouts: Cryptocurrency has been the preferred payment method for cybercriminals for a while now, especially when it comes to ransomware. As much as US$5.2 billion worth of outgoing Bitcoin transactions may be tied to ransomware payouts involving the top 10 most common ransomware variants. (FinCEN Report on Ransomware Trends in Bank Secrecy Act Data)
DDoS Attacks: The number of distributed denial-of-service (DDoS) attacks has also been on the upward trend, in part due to the COVID-19 pandemic. 2020 saw more than 10 million attacks occur, 1.6 million attacks more than the previous year. (ENISA Threat Landscape 2021)
Cybersecurity Statistics for 2022 (Infographic)
The Top 22 Security Predictions for 2022 The Top 22 Security Predictions for 2022 (govtech.com)
Dan Lohrmann is one of the world’s most knowledgeable and prolific cybersecurity experts. His article on predications for 2022
“What will the New Year bring in cyber space? Here’s your annual roundup of the top security industry forecasts, trends and cybersecurity prediction reports for calendar year 2022.
Last December in “The Top 21 Security Predictions For 2021,” I noted the following summary of expected trends for 2021:
New focuses this year cover:
Industry expert Chuck Brooks also offered these security predictions for the new year on the AT&T website. Here are two:
I only touched a tiny bit of the topics and issues relating to cybersecurity stats and predictions. Please see my analysis on protecting critical infrastructure and supply chains as we move forward in 2022. It is a large and important challenge! I will revisit new stats later in the year ad cybersecurity is never static.
Rippleshot uses machine learning and automation to detect high risk merchants and fraudulent transactions to help financial institutions protect themselves and proactively stop card fraud. Contact us today to learn more and schedule a product tour.