Security News > 2022 > August > Organizations changing cyber strategy in response to nation-state attacks

66% of organizations have changed their cybersecurity strategy as a direct response to the conflict between Russia and Ukraine, while 64% suspect their organization has been either directly targeted or impacted by a nation-state cyber attack, according to Venafi.
"We've known for years that state-backed APT groups are using cybercrime to advance their nations' wider political and economic goals. Everyone is a target, and unlike a kinetic warfare attack, only you can defend your business against nation-state cyber attacks. There is no cyber-Iron Dome or cyber-NORAD. Every CEO and board must recognize that cybersecurity is one of the top three business risks for everyone, regardless of industry."
The SolarWinds attack is a prime example of the scale and scope of nation-state attacks that leverage compromised machine identities.
Russia's recent HermeticWiper attack, which breached numerous Ukrainian entities just days before Russia's invasion of the country, used code signing to authenticate malware in a recent example of machine identity abuse by nation-state actors.
"Nation-state attacks are highly sophisticated, and they often use techniques that haven't been seen before. This makes them extremely difficult to defend against if protections aren't in place before they happen," continued Bocek.
"Because machine identities are regularly used as part of the kill chain in nation-state attacks, every organization needs to step up their game. Exploiting machine identities is becoming the modus operandi for nation-state attackers."
News URL
https://www.helpnetsecurity.com/2022/08/25/changing-cyber-strategy-nation-state-attacks/