The age of cybercrime is evolving and industrializing. To combat threats that have become easier and cheaper than ever to deploy, enterprises need to think like hackers.

Currently, 76% of malware advertisements and 91% of exploits retail for under $10, according to HP. Only 2% to 3% of threat actors today are advanced coders, highlighting the amateurism of attacks with this bargained accessibility. 

In a three-month dark web investigation, HP Wolf Security worked with Forensic Pathways to analyze more than 35 million cybercriminal marketplaces and forum posts to publish a report on cybercrime’s evolution. 

After reviewing the findings, HP Senior Malware Analyst Alex Holland, the report’s author, believes “mastering the basics” is one of three statutes necessary in defending against increasing cybercrime. As a result, he iterates three call-to-actions companies should conquer to play the better-safe-than-sorry fold.

"Mastering the Basics"

Vulnerability management is an area companies should go beyond the scope of simply having a plan — but mastering that plan by putting it to practice. “It needs to be a process that you drill into people, so it becomes part of your business as usual. You can’t plan what you don’t know about,” said Holland in a webinar last week.

Foolproof practices companies must roll out are multi-factor authentication and patch management. Also, looking at what users “actually require in terms of permissions and privileges, and taking action to reduce what software they can access” can steer companies from constantly increasing their attack surface, according to Holland. 

Investing in security controls like isolation technologies also aids in eliminating risks from “top attack vectors like email, web browsing, and file downloads,” according to Holland’s report. 

With the likelihood of breaches in today’s cybersecurity climate, the report also recommends self-healing hardware to boost a company’s resilience after a breach. 

Practice Makes Perfect

A business is only as strong as its weakest leak — and organizations should hone in on educating their workforce on best security practices. These practices can also include drills or attack “rehearsals.”

Attackers will likely outpace cyber defenders since they are not bound to the same legal or organizational constraints. “As defenders, we need to become more nimble,” Holland said. In the event of an attack, businesses should anticipate what tactics threat actors might use to recover more quickly. 

“Ensuring that everyone knows their roles and that people are familiar with the processes they need to follow will go a long way to containing the worst of the impact,” said Joanna Burkey, Chief Information Security Officer at HP, in the report, who also monitored the webinar. “If the worst happens and a threat actor breaches your defenses, then you don’t want this to be the first time you have initiated an incident response plan.”

Collaborate More — the Attackers Are

The report highlights that cybercrime is a team sport, and in order to play the game successfully, cybersecurity needs to be a team too. 

Companies can be proactive in combating threats by “involving third parties such as security assessors and penetration testing companies,” according to the report. “These can highlight weak spots and critical risks that need addressing.”

“On their own, most organizations don’t have the time or resources for this. As an industry, we need to invest more in understanding this murky world and share that information with our peers, so we can defend against it and disrupt it more effectively,” HP Security Advisory Board member Justine Bone contributed in the report.

It’s no question that more and more businesses should openly share threat intelligence amid the soar of cybercrime. Companies should use threat intelligence and be proactive in “horizon scanning”— monitoring open discussions on underground forums. 

Collaborating across industries and sharing threat information can limit the impact and frequency of attacks on organizations amid this industrial age of cybercrime.