Amid recent mass layoffs occurring across the technology industry, affected companies shouldn't overlook the potential cybersecurity risks that could leave them vulnerable to cyberattacks, security experts warned.
Tech giants like Google, Microsoft, and Amazon have recently announced tens of thousands of job cuts, which could open the door for cyberattackers looking to exploit potential chaos from this mass exodus.
“The bad actors may say: ‘hey, you've just laid off 10,000 people, I'm going to just check to make sure you're still as strong securely as you were. Or maybe I might now be able to impersonate somebody else in the organization and it's going to be easier to make my way through because I'm now talking to somebody who may not have been as experienced,’” Gartner VP analyst Paul Furtado told SDxCentral, adding that there will be some security impact if a company lays off 10% of its workforce.
Threat actors could also use the layoffs as a recruiting opportunity, he added. "They're essentially crime syndicates. They also recruit for talent,” Furtado said.
“Taking advantage of this difficult time, bad actors will most likely continue to offer ex-employees money in exchange for user credentials to gain access to critical systems and infrastructures,” Arctic Wolf CEO Nick Schneider concurred. “Everyone has a price, and we may find out what that is for some.”
CrowdStrike CTO Michael Sentonas noted that attackers are becoming more opportunistic in taking advantage of organizations that have experienced layoffs. “I won't be surprised to see a headline where an organization was targeted by an attacker because they made it publicly known that they were reducing the size of their team,” he told SDxCentral.
Job Cuts Aggravate Cybersecurity ThreatsLayoffs might also amplify insider threats, access management issues, human errors, and supply chain risks.
“The single biggest risk is around data exfiltration,” Furtado said.
Departing employees might still have the perception that they’ve created the artifact and want to take some of that information to the next company, he explained. “For example, if you are an employee in a tech company … you take some source code with you and you end up working for a competitor, well, there's now potential IP theft that comes into play,” Furtado said.
Every business is facing insider risks of data leaks or privacy abuse. However, “If a worker was laying the groundwork to do something bad, a layoff could accelerate their action – especially if employees were able to store data on personal drives,” Black Kite CSO Bob Maley pointed out.
“What we’ll find different with the current scenario around mass layoffs is that there’s a higher potential for employees to want to take action if they feel they were unfairly targeted,” Arctic Wolf's Schneider echoed, adding that desperate employees might be more likely to fall for phishing tricks and accidentally expose the company to a data breach or ransomware attacks.
Gartner’s recent research found about 56% of insider risks are the result of negligence and mistakes; 26% are due to malicious or criminal acts; and 18% are credential theft, according to Furtado.
For credential compromise, companies might be able to cut off a worker’s access, but they cannot cut the personal network and relationships. Social engineering can be leveraged as a mechanism to gain access back into the network, he said.
Additionally, third-party cyberrisks often lurk in the dark as security teams shrink, Maley said. And “bad actors often target businesses through a third party because they know it's easier.”
Turn to Security Vendors for Managed ServicesFacing these increased threats, tech companies who recently slashed jobs or cut budgets have turned to security vendors.
CrowdStrike saw managed security services gain traction and more large companies asking for help. “Larger organizations are talking to us about managed security services,” Sentonas said. “They simply don't have as many people to run the technology so they're asking us to do that on their behalf.”
Managed security services such as managed detection and response (MDR) can also benefit small and midsize businesses (SMBs) who might get impacted even more by layoffs, he added.
These job cuts also introduce additional risk to the business, which may impact the workload of their already small security team that is running at close to full capacity all the time, Furtado said, so organizations are looking to offload some of the workloads to artificial intelligence (AI) and security vendors who offer managed and automation security services.
To SMBs, “the first thing I tell them is to stop trying to do security yourself. You can't do it effectively. You need a third-party partner,” he said.
For organizations of any size, “when we take a look at large shifts in our workforce, we have to turn the lens of our security inside and develop a good insider risk management program. I think that's absolutely critical to ensure a secure exodus of those staff,” Furtado concluded.
Comments