Cyberattacks documented throughout this year have shown an increasing interest in targeting global governments and agencies. Fraught with hit after hit, governing bodies were not spared by ransomware operators in 2022 even though, out of all other sectors, they are least likely to pay out ransom demands.
Threat actors are typically driven by financial gain, but with many states considering no-ransom bills and official directives from the FBI reminding governments to refrain from paying ransom demands, what could be the motives behind the rise in public sector-focused attacks?
This blog post explores why more cyber attacks are directed at the public sector and what defenses government agencies can implement to protect against them.
Government agencies are responsible for mass amounts of sensitive data ranging from personal information about citizens to classified information pertaining to national security. In our data-centric world, information remains a hot commodity in dark marketplaces and thus paints a target on its custodians.
While attacks on businesses, healthcare providers, and educational and financial institutions make news headlines regularly, governments and their agencies have risen to the top as one of the most targeted sectors. Research in Q3 said that the government was the second most attacked industry with an attack average sitting at 1564 cases each week. This marks a 20% increase compared to the same period last year.
This year, it was reported that only 32% of state and local governments paid out cybercriminals to restore their encrypted data; a marked decrease from 42% in 2020. Compared across all other sectors which averaged at 46% in 2022, this was the lowest reported rate. Though less government bodies are paying ransoms, the number of threat campaigns is still rising, indicating that threat actors have their eyes on goals other than monetary gain.
Government entities sit atop a wealth of data due to the many services provided by the state to businesses and citizens. Even one successful breach on a government could result in leaked state-level intelligence, classified assets, and personal identifiable information (PII) to cyber criminals. In dark marketplaces, the stolen data is often sold to create forged documents, steal identities, gain initial access to organizations, or take over privileged accounts.
State-sponsored threat actors are motivated by special causes other than financial gain. Other than selling stolen data, sometimes their goal is to disrupt essential services, destroy national assets, encourage protests, expose political-level wrongdoing, or simply erode trust and provoke embarrassment.
Considered ‘soft targets’ by threat actors, state and local governments often run on small, publicly-funded budgets that save little room for robust cybersecurity programs. Government agencies may not employ dedicated security professionals and rely mainly on general-service IT or small SOC teams. Legacy technology used by this level of government may not be advanced enough to contend with the large-scale ransomware threats they are up against.
If breached, government institutions could potentially become a gateway for cyber threat actors to access thousands of other enterprises, third-party vendors, and significant amounts of the civilian population. Successful attacks on governments can have profound effects and destabilize the people they govern.
Attacking government entities can be a valuable tactic for hostile state-sponsored threat actors in political cyber warfare. Undertaking an ‘influence operation’ through malicious cyber techniques allows actors to position false narratives in the public domain and amplify a story in line with their goals.
Many government IT systems are three for three when it comes to digital security red flags:
These red flags are typically the result of a weak IT and cybersecurity infrastructure – a common problem that plagues poorly-funded government agencies. Though the public sector is often the victim of opportunistic attacks, governments are also being targeted by sophisticated attackers who are abusing their weak infrastructures to deploy malware, lateral movement tools, ransomware, and phishing.
The global shortage of cybersecurity expertise is compounding the issue of weak government IT systems. Based on a recent study released by The International Information System Security Certification Consortium, known as (ISC)², the current cybersecurity workforce gap amounts to 3.4 million open roles needing to be filled. The study described today’s threat landscape as being a volatile one; directly shaped by this year’s macroeconomic and geopolitical turbulence.
As state and local governments work around tighter budgets, this usually means there are scarce (if any) cybersecurity resources dedicated to supporting agencies. Lack of security expertise leaves the agencies susceptible in the long run. Without cybersecurity expertise embedded in leadership and collaborating with technical teams, poorly-funded governments face the risks of:
Governments offer many public services, which all feed into the complexity and size of their attack surface. For governing bodies to continue providing those services safely, CISOs need to consider leveraging a simple, streamlined, end-to-end security strategy that can cover all of the inherent risks they face in the current landscape.
Following the conflict between Ukraine and Russia, the CISA issued a Shields Up alert warning all “within and beyond the region” to be prepared and responsive to disruptive cyber incidents. The warning cites the “economic costs imposed on Russia by the U.S. and our allies and partners” as a potential reason for the Russian government to consider escalating its actions to nations outside of Ukraine. Shields Up recommends actions such as:
President Biden’s national security memorandum from last summer underscored the need for building cyber-resilient infrastructure and systems. In response to this release, NIST and CISA jointly released new Cybersecurity Performance Goals (CPGs) to help critical infrastructure sectors kickstart their security efforts. Described by CISA as a minimum set of best practices, the CPGs provide actionable goals on the topics of account, device, and data security.
At the root, account, device, and data security all start at the identity surface. As more high-value sectors move towards remote workforces and create digital identities to share information and collaborate, that surface widens, leaving them vulnerable to identity-based exploitation. By looking at identity as the new network perimeter, enterprises can scale down that attack surface by detecting threats in their earliest stages.
Before the data loss stage, enterprises that can identify over-privileged users, cached credentials, and other identity-related cyber hygiene issues can prevent the initial breach from happening at all. The importance of identity threat detection and response will only grow as threat actors leverage weak endpoints and social engineering tactics to find their way into networks.
Governments managing immense databases especially need to reduce the changes of cyber intrusion by implementing identity authentication security solutions (e.g., MFA), endpoint detection and response (EDR), remote access validation, privileged account audits, and stringent password policies.
Advanced cyber threats such as ransomware, phishing and whaling campaigns, and DDoS attacks have beleaguered governments globally in 2022, taking malicious advantage of their sluggish policies and departmental silos. Up against uniquely motivated threat hacktivists and data-hungry cybercriminals, governments have found themselves at the number two spot in most attacked sectors this year.
Reported attacks from this year alone clearly indicate that this critical sector needs to advance its cyber resiliency and implement cybersecurity best practices to reduce its attack surface. Solutions that provide complete visibility are most effective, given the breadth of data networks managed and processed by governments and agencies.
Solutions should leverage identity-based security tools capabilities leveraging artificial intelligence (AI) and machine learning (ML) to fight back against ransom operators and sophisticated social engineering schemes. Removing limited network visibility ensures governments can monitor endpoints and data more effectively while detecting and responding in real-time to security events before they can lead to catastrophe.
While no entity is immune from cyber attacks, governments can examine the top attacks reported in 2022 through an educational lens to secure better the data of those relying on their services. Learn how SentinelOne can help enterprises build cyber resilience through autonomous endpoint protection by contacting us today.