Cyber threats are becoming more sophisticated – Adley Francois on AI, nation-state attacks and why organisations are still not prepared

Adley Francois

By Viesturs Deksnis, Editor-in-Chief of Balticnews.com.

Cybersecurity threats are becoming more frequent, more sophisticated and increasingly intertwined with geopolitical tensions. At the same time, artificial intelligence is giving attackers new tools to operate faster and at greater scale.

Speaking with Balticnews.com, Adley Francois of Kevlar Defense discusses how the global cyber threat landscape has changed, the growing role of nation-state actors, the most common ways attackers penetrate organisations, and why awareness of cybersecurity risks has still not translated into sufficient preparedness.

He also warns that Latvia and the wider Baltic region should expect more sophisticated cyberattacks against critical infrastructure – and argues that organisations and governments need to prepare not only to prevent attacks, but also to continue operating and recover when an attack succeeds.

How would you describe today’s global cyber threat landscape? Has it fundamentally changed over the last few years?

I would say so. I think there are a couple of factors driving the threat landscape.

What continues is that there are always going to be ransomware-type attacks where the primary motivation is money. Those attacks have been around for some time.

What has changed lately is that nation-state threat actors have been very, very active when you consider the geopolitical situation globally. And when you include the speed of AI, it has made attacks a lot more efficient.

So I think those three factors are the driving forces that I am seeing: you have the monetary value, you have the geopolitical situation, and when you add AI into the mix, we are seeing more attacks than ever before.

Can any organisation become a target?

Yes. It is across the board – small organisations, government agencies and multinational companies.

People sometimes still imagine a hacker as one or two people sitting behind a computer. What does a modern cyber threat organisation actually look like today?

Again, in some cases you are looking at hundreds of people, especially in the case of nation-state actors.

From the ransomware investigations you have handled around the world, what are the most common ways attackers gain access to an organisation’s network today?

We do hundreds of ransomware investigations annually, and the most common vectors are going to be three things.

One is identities that have been stolen – usernames and passwords that have been stolen and are available on the dark web for sale.

There is a market where usernames and passwords can be purchased.

On top of that, there are unpatched vulnerabilities. That is going to be key. There is a window between the time a vulnerability is actually discovered and when a fix is actually released or applied. That window is what a lot of threat actors are leveraging.

And then, on top of that, phishing has always been a way inside a company.

Artificial intelligence is transforming almost every industry. How is AI changing cybercrime, and can it also become one of the strongest tools for cyber defence?

You can create a perfectly crafted email for an individual or an organisation.

The ability to leverage AI to actually do research on an individual or a company means you can now do that at scale.

But at the same time, there is also the ability to perform analysis quickly. So cyber defenders have this additional tool now as well.

The Baltic region is facing cyberattacks, GPS jamming, disinformation campaigns and even acts of physical sabotage linked to Russian hybrid operations. Are these still separate threats, or are they increasingly becoming part of one coordinated strategy?

I think those strategies are now merging.

The cyber element used to focus primarily on influence campaigns. When you look at various U.S. elections and things of that nature, those were primarily influence-based – trying to influence the outcome of an election and things of that nature.

But at this stage, we are seeing multiple attacks against critical infrastructure that have national implications.

That includes transportation, the power grid and healthcare.

So the nature of the attack is actually quite different. It is not just influence. There is sabotage.

Cyberattacks against organisations such as Latvijas valsts meži have attracted significant public attention. Based only on the information that has been made public, what does this incident tell us about the current state of cybersecurity in Latvia?

Unfortunately, due to the geopolitical situation there, I can see those attacks increasing.

Most organisations are not ready for this kind of sophistication.

I think in this particular case, Latvia and the Baltic region are going to see more and more of these sorts of attacks, and critical national infrastructure has to be ready.

It has to be tested at regular intervals.

When a cyberattack happens, what should be the first step from a technical perspective?

From a technical perspective, there is a flow for doing this.

One thing that you want to do the minute this happens is make sure that the threat is contained within the environment.

You have to know all of the entry points inside the environment.

From a network perspective – whether it is a VPN or primary and secondary internet connections – you have to have perimeter domains where you know all of the possible entry points.

From there, you establish some kind of control, meaning that you are going to limit inbound and outbound traffic.

What are the main cybersecurity services your customers are currently requesting from Kevlar Defence?

I would say incident response is our number one service.

Essentially, a customer purchases a block of hours, and when something happens, we can deploy a team on behalf of the company or an agency.

That can involve forensic analysis, threat containment, Active Directory and a number of capabilities that you are going to need in order to respond to an attack.

With just one phone call, you can literally have hundreds of subject-matter experts deployed on behalf of a company. I think that is the number one service.

Outside of that, when you look at the threat landscape and the various threat vectors, we have a number of services that address those directly.

Phishing attacks are going to be one of the number one ways in, so we have a phishing simulation service.

Outside of that, we have training services where we can train government and private-sector employees to make sure that they do not fall prey to cyberattacks.

And we also have 24/7 security monitoring services.

Has the mindset of organisations towards cybersecurity changed over the past five or ten years, or do you still need to convince them that this is a real threat?

I think most organisations have some awareness as far as cybersecurity is concerned.

But what is missing is translating that awareness into an action plan or turning that into a budget.

Basic awareness is there. But have organisations turned that into action? I don’t think we are quite there yet.

Even with the awareness level, I don’t think that has translated into an understanding of how catastrophic cyberattacks could be.

Most organisations do a pretty good job of managing other sorts of risks, but I don’t think most have reached the internal conclusion that a cyberattack could actually bring an organisation – or even a nation – to its knees.

When you think about the power grid, hospitals and banks, all of those organisations could be shut down for days, and in some cases weeks.

If you compare the public and private sectors, are there significant differences in their cybersecurity preparedness?

The private sector is probably a lot more educated on the topic.

In the public sector, I think funding is lacking. I think the education is there, but from a funding perspective, the ability to commit resources is more limited.

The private sector is a lot more prepared in that aspect, I think.

During the recent blackout in Spain, electricity, internet and mobile communications were unavailable, while uncertainty and disinformation spread quickly. Regardless of what caused that particular incident, it demonstrated how disruptive the loss of critical infrastructure can be. What should governments around the world be doing to prepare for scenarios of this scale?

It is not just about prevention.

I think governments need to change their imagination a bit when thinking about what the worst case is going to be.

Whatever you think a cyberattack is going to look like, the real thing is going to be ten times worse.

So you have to prepare for those particular cases and come up with alternate plans for how you are going to operate.

Beyond that, you need a plan for how you are going to get systems back up and running.

Most organisations that I am aware of have an incident response plan, and that plan generally has a recovery timeline of one day. In some cases, we are seeing it down to hours.

Within the banking industry, there are sophisticated plans created by consultants where the recovery timeline can be four hours.

The key is that those plans have to be tested before the real thing happens.

PLEASE WATCH THE FULL VIDEO INTERVIEW HERE:

Share this article

related News