Mandiant and parent company Google are tracking significant increases in zero-day exploitations, and cloud and infrastructure attacks, though they are also seeing improved security resiliency counter moves by organizations. This insight was provided by Mandiant CEO Kevin Mandia and Google Cloud CISO Phil Venables during this week's mWISE event.
Mandia based his insight on the last 1,000 intrusions that Mandiant responded to over the last year, conversations he has had with around 400 CISOs, and input from its 350 threat analysts that speak 34 languages from 26 countries. That insight led Mandia to note a handful of cybersecurity trends.
First, he noted zero-day exploitation is “at a very heightened level,” as this year the company has so far tracked 36 attacks, “that means we're going to end up at 43.9 zero days this year,” compared to the current record of 32 that were made in 2019.
Meanwhile, threat actors using exploitation via valid credential or spear phishing for their attacks is also on the rise.
However, Mandia also noted that more organizations are paying attention to building security resilience. “The goal of resilience, whether it's a hurricane, earthquake, or ransomware, it's all the same as disaster recovery to some extent, is to be able to answer the question that the CEO or shareholders will have, which is simply: so how long before you're up and running?” Mandia said. “I do believe [after] a year or two, the vast majority of companies will be able to answer that question.”
Echoing those observations, Venables listed three top security challenges that Google Cloud customers are facing: how to manage security information and cyberrisks in hybrid and multi-cloud environments with large numbers of software-as-a-service (SaaS) services; how to accelerate technology modernization in partnership with technology and business teams; and how security teams support speed and agility of the security operation, business, or the organization’s mission.
Mandiant: ‘The Future Is Predictable’Looking ahead, Mandia expects more security threats from destructive attacks, attacks on cloud and infrastructure, disinformation and influence operations, and the metaverse.
He is also seeing an evolution of board governance to where the expectation of the board of directors is to understand cyberrisk.
Both Mandia and Venables touted the integration of Mandiant and Google Cloud will help the development of security automation and embedded cloud security.
Last year, Google Cloud announced plans to invest another $10 billion on security over the next few years, “because we think it's that important to bake security into the platform and into the infrastructure,” Venables said, adding that it also invests in open source and open standards to promulgate security across the industry.
Other focus areas for Venables next year include authentication, operating systems, hypervisor, software supply chain security, a shared responsibility model in the cloud, and building a digital immune system.
Comments