The first half of 2024 has presented an unusual trend in the cybersecurity landscape: a slowdown in cyberattacks. For three consecutive quarters at Corpay, overall attack metrics are down, painting a slightly calmer picture than normal. However, as industry experts will attest, this period of tranquility could be the quiet before the storm.
A Shift in Cyberattack Patterns
While the general reduction in cyberattacks is a positive development, the cybersecurity community remains cautious. Recent high-profile breaches serve as a stark reminder of the persistent threat landscape. CDK Global, a prominent ERP provider for car dealerships, suffered a significant cyberattack, incapacitating 15,000 dealerships’ ability to sell, finance, or service cars. This incident underscores the vulnerability of critical service providers and the potential widespread impact of targeted cyberattacks.
Similarly, the Snowflake incident that led to a data breach at Neiman Marcus further highlights the evolving threat vectors targeting large enterprises. The LockBit ransomware group also made headlines with their attack on Evolve Bank, resulting in leaked data and heightened concerns about the security of financial institutions, including false claims of a Federal Reserve data breach that would have sent shockwaves through the financial markets. AT&T announced hackers obtained months’ worth of data on its customers’ calls and texts. They didn’t get personal information, but it was an unnerving breach nonetheless.
The healthcare industry is especially vulnerable, since their industry is risk averse and therefore more willing to pay the ransom. This is especially true among smaller, rural hospitals that don’t have the budget to support a robust cyber defense. That prompted the White House to ask Microsoft and Google to provide free or low-cost cybersecurity protection to rural hospitals across the country.
Catching the Bad Guys
Law enforcement is trying to do its part to further slow cyberattacks. Case in point the recent arrest of the Scattered Spider hacking group leader, a 22-year-old British man in Spain. Scattered Spider, which hacked the MGM Resorts last year, is expected to continue its criminal ways despite the arrest of its ringleader. The dumping of stolen data also continues, although much of the data offered for sale is recycled and stale. This does not, however, reduce the necessity for robust cybersecurity measures.
The Whole World is Watching
A potential uptick in cybercrime may be driven by the calendar. As the Paris Olympics approach, hacktivists upped their denial of service attacks on France, presumably as a practice run ahead of the games. Also, with the election season upon us, we can expect a surge in AI-generated disinformation and misinformation campaigns. These will likely include frightfully realistic deep fakes of candidates or company CEOs making disruptive statements in the runup to November 5.
Strategic Recommendations for Cybersecurity Leaders
Given the current landscape, it is imperative for cybersecurity leaders to adopt a proactive stance. Here are five key recommendations for navigating the remainder of 2024:
- Establish a Clear Definition of Success: Success in cybersecurity should encompass both preventive and responsive measures. This means implementing robust defenses to thwart potential attacks and having a comprehensive recovery plan to minimize damage if an attack occurs.
- Take Proactive Measures: Take advantage of the downturn in cyberattacks to develop and deploy proactive steps tailored to your organization’s specific threats. This includes regular updates and patches, employee training on recognizing and responding to phishing attempts, and continuous monitoring for unusual activities. Check for any new networks or products that are exposed to the Internet and could be exploited.
- Talent Acquisition: Hire and retain the necessary talent to execute your cybersecurity strategy effectively. This involves investing in skilled cybersecurity professionals who are adept at both defense mechanisms and incident response.
- Leverage Advanced Technologies: Utilize advanced technologies such as AI and machine learning to enhance threat detection and response capabilities. These technologies can help in identifying patterns and anomalies that may indicate a potential attack.
- Focus on Resilience: Ensure that your organization’s cybersecurity strategy includes a strong emphasis on resilience. This means having robust backup systems, disaster recovery plans, and clear communication protocols to manage and mitigate the impact of a cyberattack.
Conclusion
The first half of 2024 has indeed been marked by an unusual lull in cyberattacks. However, this period of relative calm should not lead to complacency. The high-profile breaches and the potential for increased disruptive campaigns in the latter half of the year underscore the need for continuous vigilance and preparedness. By defining success, taking proactive steps, and hiring the right talent, cybersecurity leaders can navigate the challenges ahead and bolster their defenses against the ever-evolving threats.


