Listen to this episode

10 Cybersecurity Facts that Shock Even Security Experts

0:0048:58

Recorded April 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode, Erin, Blake, and Dwight of Petronella Technology Group walk through cybersecurity statistics and trends from a recently published CompTIA resource. Blake highlights a Microsoft finding that nearly 80 percent of nation state attackers targeted government agencies, think tanks, and NGOs, prompting a discussion of cyber warfare and how devastating a power grid attack could be.

Dwight points to supply chain attacks and rising identity theft, and the group debates social media oversight, misinformation, and Elon Musk's offer to buy Twitter. Blake cites a Purple Sec statistic that 98 percent of cyber crime relies on social engineering. The hosts examine healthcare breaches, noting that healthcare invests less than six percent of its budget on cybersecurity and that 88 percent of healthcare workers opened phishing emails, and they stress that 77 percent of organizations lack an incident response plan. They also discuss pandemic-era incident increases, cyber insurance that at the time of recording required compliance, and close with recommendations covering staff education, multi-factor authentication, penetration testing, threat monitoring, and XDR.

Worth remembering

Key takeaways

  1. Train staff to recognize attacks like phishing; Erin calls employees the leading cause of data breaches, noting most do not act on purpose.
    “Train your staff, to recognize different types of attacks, such as phishing and email stamps.”
  2. Enable multi-factor authentication; Erin says it makes a hack 90 plus percent less likely, comparing attackers to robbers who avoid well-protected houses.
    “if you have multi-factor authentication, it's 90 plus percent, you're not going to get hacked versus. People that don't.”
  3. Write an incident response plan before a breach; the hosts cite that 77 percent of organizations lack one, which adds to breach costs.
    “another alarming status, super alarming, and this kind of leads more into compliance, but of organizations do not have an incident response plan.”
  4. Do not treat cyber insurance as a substitute for security; Dwight explains that at the time of recording insurers required compliance and audit proof.
    “The thing is you have to have compliance in order to get your cyber insurance.”
  5. Remember that people are the weak point; Blake cites a Purple Sec figure that 98 percent of cyber crime relies on social engineering.
    “according to purple sec, 98% of cyber crime rely on social engineering to be successfully accomplished”
  6. Medical centers should require proximity tokens for computer access; the hosts call them cheap, convenient protection after Erin saw an exposed terminal.
    “if you're a medical center, you need proximity token. We can say that.”
  7. Take cybersecurity seriously before an attack strikes; Blake warns that one incident can undo 20 years of business growth.
    “you can spend 20 years growing your business. And one incident can take you down”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

We told you the top cybersecurity myths that you need to forget immediately; now we are going to let you in on the shocking reality that is the cyber realm. From insidious Russian viruses to the vast amount of simple human error, nothing is what it seems in the digital age!

Link: Top 50 Cybersecurity Statistics, Figures and Facts Hosts: Blake, Dwight, and Erin

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.