Alerts and Advisories
What Are Cybersecurity Threats?
Cybersecurity threats are malicious acts that seek to damage data, steal data, or disrupt digital life in general. These threats can target individuals, businesses, or governments and may result in financial loss, privacy violations, operational disruptions, or reputational damage.
Common Types of Cybersecurity Threats
Unauthorized Access/Infiltration: Break-ins due to weak credentials or security flaws, allowing intruders access.
- Enable Multi-Factor Authentication (MFA)
- Strong password policies
- Regular security audits
Exploitation of Vulnerabilities: Attacks leveraging unpatched or zero-day vulnerabilities in software or hardware.
- Apply patches promptly
- Regular vulnerability scanning
- Intrusion detection systems
Denial of Service (DoS) and Distributed Denial of Service (DDoS): overwhelming a service with traffic, sometimes impacting availability.
- Use CDN protection
- Firewall configuration
- Traffic filtering
Insider Threats: Malicious or negligent actions by trusted insiders compromising security.
- Role-based access control
- Employee security training
- Activity monitoring
Phishing: deceptive messaging designed to elicit usersβ sensitive information (such as banking logins or business login credentials) or used to execute malicious code to enable remote access.
- Verify sender
- Avoid suspicious links
- Email filtering systems
Ransomware: a tool used to lock or encrypt victimsβ files until a ransom is paid.
- Regular backups
- Install updates
- Endpoint protection software
Social Engineering: Manipulative tactics (pretexting, baiting) used to deceive individuals into revealing confidential information.
- Security awareness training
- Strict verification procedures
- Clear reporting channels
Malware: a Trojan, virus, worm, or any other malicious software that can harm a computer system or network.
- Install antivirus software
- Avoid unknown downloads
- Keep systems updated
Zero-Day Exploits: Attacks exploiting previously unknown vulnerabilities before they can be patched.
- Advanced threat detection
- Network segmentation
- Defense in depth strategy
Supply Chain Attacks: Compromises in third-party vendors or software that impact the primary organization.
- Vendor risk assessments
- Software integrity validation
- Strict third-party access control
Data breach: unauthorised access and disclosure of information.
- Encrypt sensitive data
- Access control management
- Regular security audits