4 Reasons Cybersecurity Attack Surfaces Are Expanding

August 24, 2021

The COVID-19 pandemic impacted individuals and businesses all over the world in one way or another. Almost overnight, it disrupted the way people went about their daily routines and how companies operated. Amidst all the chaos, changes to the cyber landscape increased at an unprecedented pace. Some of the trends that powered these changes and continue to fuel them are:

  1. Increased Use of Internet of Things (IoT)
  • About 56 federal agencies in the U.S. reported using Internet of Things (IoT) technologies.1
  • In 2021, experts expect the number of connected devices to reach 10.07 billion.2
  1. Rapid Adoption of the Cloud
  • Global public cloud end-user expenditure is expected to grow by over 18% in 2021.3
  1. Digital Transformation
  • IT spending is expected to hit $3.9 trillion in 2021.3
  • Spending on digital transformation technologies increased from $1 trillion in 2018 to $2.39 trillion in 2021.2
  1. Work-From-Home Model
  • Over 70% of all departments and teams are expected to have remote workers by 2028.

With an expanding attack surface comes cybercrime. According to an FBI report, cyberattacks have skyrocketed by over 400% since the start of the pandemic, making it imperative to identify and deflate cyberthreats for the health and future of your business.

Growing Cybersecurity Risks

  1. Targeted Ransomware Attack

Ransomware attacks have long been a nuisance to businesses. Experts have estimated that about 10% of breaches reported in 2021, so far, involved ransomware.5 The success of this mode of attack is attributed to the simplicity with which an attacker can wreak havoc. It should worry everyone that ransomware kits are inexpensively available on the dark web.

Ransomware propagators are constantly devising new plans to evade defenses set by businesses. Without precautionary measures in place, SMBs could find themselves at risk.

  1. Phishing Attacks

Phishing uses social engineering in email and cloud services attacks. Phishing attacks can lead to account takeover, credential theft and more. According to one report, phishing attacks increased by 11% in 2021 alone.5

Malicious actors using phishing scams as their method of attack are cunning enough to tilt every global event to their advantage. For example, when the pandemic started, phishing emails were sent out to the masses in the name of the World Health Organization (WHO). Later, when vaccines were rolled out, scam emails had a vaccine company’s name as the sender.

  1. Insider Threats

Shockingly, close to 20% of breaches involve internal actors.5 The problem with insider threats is that they’re often the toughest to detect.

The most common causes of inside incidents are:

  • Negligent employees or contractors6 – 62%
  • Criminal or malicious insiders6 – 23%
  • Credential theft6 – 14%
  1. Fileless Attacks

A fileless attack aims to exploit the features and tools of a victim’s environment. It doesn’t depend on file-dependent payloads nor does it generate a new file. This leaves no footprint and makes fileless attacks very hard to detect. A fileless attack is reported to be 10 times more successful than a file-based attack.7

Fileless attacks can originate through an email that directs you to a malicious website. From there, using social engineering tactics, the cybercriminal can use system tools (such as PowerShell) to distribute payloads and execute commands. Since these system tools are part of your IT environment, the threat can evade outdated security systems.

How to Stay Protected

You can ramp up your IT security and protect your business by following these steps:

  • Keep your systems updated and safe from cyberattacks that exploit known software vulnerabilities by automating patch and vulnerability management.
  • Ensure effective and quick recovery from cyber disruption by backing up your systems and SaaS applications.
  • Secure your systems by deploying advanced antivirus and antimalware solutions that provide endpoint detection and response (EDR).
  • Make sure every new device has the necessary security tools to start with — local firewall, DNS filtering, malware protection, multifactor authentication (MFA) and disk encryption.
  • Always be ready with an incident response plan. No breach can shake you if you have a robust action plan. The plan should have a communication strategy with all stakeholders, including your investors and valued customers.
  • Provide regular security training to your employees and vendors.

If thinking about assessing your current cybersecurity posture gives you anxiety and you’re not sure where to start, don’t worry. We can take the assessment off your plate and suggest the right solutions for your business. An experienced partner like us can make your cybersecurity journey seamless and successful. Contact us today for your cybersecurity assessment.

Sources:
  1. US GAO-20-577 Report
  2. Statista
  3. Gartner
  4. Upwork Report
  5. Verizon 2021 DBIR
  6. 2020 Cost of Insider Threats: Global Report
  7. Ponemon Institute

Recent Post

April 28, 2025

The Dark Side Of Chatbots: Who’s Listening To Your Conversations?

Chatbots offer convenience, but they also raise serious privacy concerns. Many chatbots collect, store, and analyze user conversations without explicit consent. This data can be exploited for targeted ads, sold to third parties, or even breached in cyberattacks. Some chatbots use AI to "learn" from interactions, potentially exposing sensitive personal or corporate information. The article explores who has access to these conversations, how the data is used, and what users can do to protect their privacy in an era of increasingly intrusive AI.
Read More
April 21, 2025

Hackers Might Not Ransom You Anymore – They’ll Just Extort You Instead!

Cybercriminals are shifting from ransomware to direct extortion—stealing and threatening to leak sensitive data unless paid. Businesses must strengthen cybersecurity to avoid becoming victims of this growing threat.
Read More
April 14, 2025

What Happens To Your Applications When Windows 10 Support Ends?

Businesses face significant risks when Windows 10 support ends on October 14, 2025. Without security updates, applications become vulnerable to cyberattacks, compatibility issues, and a lack of technical support. This can lead to data breaches, productivity disruptions, and increased downtime. Businesses should back up their data, consider upgrading to Windows 11 or replacing hardware, and partner with a trusted IT provider for a smooth transition. A free network assessment is recommended to evaluate current systems and plan for a secure and efficient upgrade.
Read More
© 2025 Core Technologies Services, Inc. All rights reserved.