Make life difficult for cyber criminals

Make life difficult for cyber criminals

This year’s Cyber Security Awareness Month is encouraging us to “Make Life Difficult for Cyber Criminals” and I think this is a really useful way of looking at security awareness. 

We cannot stop criminals from targeting our organisations and we cannot expect every employee to recognise every attempt. What we can do is reduce the opportunities available to an attacker and make sure that one mistake, one compromised account or one weakness is not enough to get them where they want to go. 

Attackers tend to take the route that gives them the best chance of success. There is no need to spend time attacking a well protected system if an old account, an exposed service, a supplier with unnecessary access or a convincing phone call gets them to the same place. That is why awareness is so important, in addition to the wider security controls an organisation already has in place. 

Social engineering is getting harder to spot 

A good social engineering attempt will often work because it does not look particularly unusual. Finance teams process payment requests, executives message colleagues while travelling, suppliers change bank details and employees receive links to documents, meeting invitations and shared files every day. If you understand how an organisation works, it becomes much easier to make a malicious request look like part of that normal activity. 

There can also be much more research behind an approach than the person receiving it realises. LinkedIn, company websites and social media can tell an attacker a surprising amount about who works where, reporting lines, suppliers, projects and events. Information from previous data breaches can add another layer of detail. Sometimes something as simple as knowing that a senior colleague is travelling is enough to make an approach more believable. 

An attacker does not need to know everything about somebody. They just need enough to make the request feel credible at the point it arrives. 

AI is making some of these attempts harder to spot. Messages can be well written and tailored to the recipient, while developments in voice and image generation give attackers more options for impersonating people. We have spent years telling employees to look for poor spelling, strange language and other obvious signs of phishing, but increasingly those signs may simply not be there. 

We need to be careful, therefore, about making the employee our main defence against this. You do not want your security to depend entirely on one person recognising a problem at exactly the right moment. People will make mistakes, including people who understand security very well, so the controls around them need to allow for that. 

Awareness training matters, but there will always be occasions when somebody clicks a convincing link, approves something they should have questioned or responds to a request that seemed entirely reasonable at the time. 

What happens when somebody gets it wrong? 

For me, this is the more useful question. 

If somebody’s password is weak, re-used or ultimately compromised, is MFA in place to make that password less useful? If an unusual payment request appears to come from a senior colleague, is there another way of verifying it before money leaves the business? If somebody convinces the IT service desk that they are a legitimate employee, what has to happen before an account can be reset? 

This is where the controls around people become important. The aim should be to make sure that compromising a password, convincing one employee or getting access to one account does not automatically give an attacker what they want. The more opportunities there are to contain, challenge or detect what happens next, the harder it becomes to turn that initial success into something more serious. 

It is also worth thinking about what happens after the first compromise. If an attacker gets into one account, what can they actually reach from there? If they gain access to one system, does that give them a route into others? Would unusual activity be noticed and, if it was, would somebody be able to act on it quickly? 

You do not want your security to depend entirely on one single source of failure. People will make mistakes, including people who understand security very well, so the controls around them need to be layered to allow for that. 

What happens after a mistake is made? 

We also need people to tell us quickly when something has gone wrong. 

If an employee enters their credentials into a phishing site and reports it immediately, the security team has an opportunity to secure the account, investigate what happened and look for any further activity. If that individual spends the next half an hour worrying about whether they are going to look foolish or get into trouble, the attacker has another half an hour to use those credentials. 

That time can matter. People need to know how to raise a concern and feel comfortable doing it, including when the request they are questioning appears to come from somebody senior. There is little point telling employees during annual training that they should challenge unusual requests if, in reality, questioning a senior colleague is not particularly welcome. 

Security teams have a part to play in this too. If a secure process consistently makes it difficult for somebody to do their job, there is a good chance they will eventually find another way of doing it. It is easy to label that as poor security behaviour, but sometimes the workaround is telling you something useful about the control itself. 

That does not mean removing controls because people find them inconvenient. It means understanding how security works in practice rather than assuming a policy or process is effective simply because it exists. 

Where would you start? 

Cyber Security Awareness Month is a good opportunity to look at your organisation from the other side and ask where you would start if you were trying to get in. 

Which accounts would be useful? Which processes rely heavily on trust? What could you learn about the organisation and its people without touching its systems? Who could you plausibly impersonate? Which suppliers have access and how much? If you did compromise an account, what could you access and would you be detected? 

These questions can tell you a lot about where the real opportunities sit. Some will come down to technology, others to access, processes or the information people share, but often it is the combination that creates the opportunity an attacker needs. 

People get busy, controls fail, vulnerabilities exist and sometimes an attacker has done enough homework to make something look completely legitimate.  

For me, making life difficult for cyber criminals means getting the basics right, then layering your defences so that one gap does not give them the keys to the kingdom. 

 Author – Katie Barnett, Director of Cyber Security