Why Top-Regulated Firms Must Invest in Advanced Cybersecurity Solutions

As organizations race to address the vulnerabilities revealed by CrowdStrike’s extensive IT outage on July 19, cybercriminals are seizing the opportunity by posing as CrowdStrike in phishing schemes. They are masquerading as genuine support entities to infiltrate corporate networks and gain unauthorized access.

“When systems are down, hackers find the perfect window to exploit your data,” remarked Javad Abed, an assistant professor of information systems at Johns Hopkins Carey Business School. “This is why implementing multiple security layers is essential. Redundancy is crucial. You must assume threats are inevitable and design your security framework around a zero-trust model.”

The CrowdStrike event, which disrupted sectors such as healthcare, airlines, and financial services, and inflicted a $500 million loss on Delta Air Lines alone, underscores that even top-tier cybersecurity firms are not immune to breaches. This incident highlights the urgent need for reassessing defenses, especially in highly regulated industries where the stakes are particularly high and threats continually evolve.

This situation raises a pressing question: In a time when cyber threats are becoming increasingly sophisticated, are regulated industries elevating their cybersecurity measures adequately?

Abed believes more action is needed. “Many business owners still view security as an expense, not an investment,” he said. “Security spending should be seen as an investment rather than a cost.” Industries such as finance and healthcare need to customize their defenses with high-grade security measures, according to Abed.

Military-grade cybersecurity, according to Abed, is a proactive approach focusing on prevention rather than detection. It involves advanced threat intelligence, real-time data analytics, machine learning, and predictive modeling, along with the highest encryption standards and sophisticated access control systems, including biometric verification and smart cards. Traditional cybersecurity methods, by contrast, emphasize detection and response, relying on less stringent encryption and simpler authentication methods.

Implementing military-grade cybersecurity poses challenges such as high costs, the need for specialized personnel, and potential compatibility issues with existing systems. “Some of these advanced strategies may disrupt operations or be cost-prohibitive, making them impractical for some organizations,” Abed noted.

A balanced approach might be more feasible, he suggested. “Gradually integrating these technologies and strategies, while assessing how much can be adjusted in different aspects of business operations, seems the most practical solution.”

Sensitive information handlers remain prime targets for cyber breaches. In 2024, regulated industries have experienced a notable rise in both the number and financial impact of data breaches. The healthcare sector tops the list with an average breach cost of $9.77 million, followed by finance at $6.08 million and industrial sectors at $5.56 million. Technology also sees significant costs, averaging $5.45 million per breach, according to the latest IBM and Ponemon Institute report.

These sectors face stringent cybersecurity requirements, and non-compliance can lead to substantial fines, as highlighted by Cole Two Bears, vice president of security services at ThinkGard. This issue extends beyond the U.S., with significant penalties imposed globally, such as China’s $1 billion fine against Didi and Amazon’s $877 million fine for GDPR violations in 2021.

The threat landscape is shifting. The 2024 Verizon Data Breach Investigations Report shows a 180% increase in exploitation of vulnerabilities as an initial breach method since 2023. Organizations take an average of 55 days to address half of their critical vulnerabilities, giving attackers ample time to exploit these weaknesses.

Human error remains a significant factor in breaches, accounting for 68% of incidents, including phishing and data mishandling. Credential attacks have comprised 33% of breaches over the last decade, while supply chain attacks have risen from 9% to 15% since 2023. Ransomware attacks have surged by 74% globally in the past year, according to Avril Haines, Director of National Intelligence, in a May hearing on global threats.

Notable breaches over the past year include AT&T’s extensive data breach affecting nearly all its 241 million wireless customers, the Cencora breach impacting data from 11 major drug firms, and the cyberattack on UnitedHealth’s Change Healthcare, which compromised data for roughly one-third of Americans and incurred a $22 million ransom.

Two Bears predicts worsening conditions, citing generative AI as a major factor and pointing to Gen Z as a rising threat due to economic despair. “Over the next five years, unless the economic situation improves, we might see Gen Z engaging in fraud due to their bleak outlook,” he said.

Abed concurs, noting that economic difficulties can drive internal threats as well. “Economic pressures can lead employees to commit intentional attacks.”

Despite the robustness of military-grade cybersecurity, the human element remains critical. Regulated industries must balance advanced technology with effective personnel management and comprehensive employee training, according to Gary Orenstein, chief customer officer at Bitwarden.

“Ultimately, it boils down to people,” Orenstein said. “Most breaches are linked to employee behavior. Ignoring this is no longer an option given the severe consequences.”

Frederic Rivain, chief technology officer of Dashlane, presents a different perspective. He argues that while military-grade defenses are valuable, human error is still the most common cause of breaches. He stresses the importance of education and good practices over advanced technologies.

“Security is fundamentally about common sense. Ensuring employees follow good credential practices and avoid unnecessary risks is key,” Rivain said.

However, Two Bears warns that despite robust employee education, the increasing sophistication of phishing attempts powered by generative AI makes it challenging to identify fraudulent emails.

“Multifactor authentication is vital, but it must be part of a multilayered defense,” Two Bears emphasized. “Without comprehensive protection, threat actors can still find a way in.”

More Articles & Posts