Cybersecurity Trends & Statistics For 2023 - Chuck Brooks
Cybersecurity Trends & Statistics For 2023 - Chuck Brooks
FORBES INNOVATION AI
Every year I peruse emerging statistics and trends in cybersecurity and provide
some perspective and analysis on the potential implications for industry and
government from the data. While cybersecurity capabilities and awareness seem
to be improving, unfortunately the threat and sophistication of cyber-attacks are
matching that progress.
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 1/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
Blue glowing futuristic technology, computer generated abstract background, 3D render GETTY
For 2023 and beyond the focus needs to be on the cyber-attack surface and
vectors to determine what can be done to mitigate threats and enhance resiliency
and recovery. As the interest greatly expands in users, so do the threats, As the
Metaverse comes more online it will serve as a new vector for exploitation.
Artificial intelligence and machine learning, while great for research & analytics
(i.e. ChatGPT). However, AI tools can also be used by hackers for advanced
attacks. Deep fakes are already being deployed and bots are continuing to run
rampant. and the geopolitics of the Russian invasion of Ukraine has highlighted
the vulnerabilities of critical infrastructure (CISA Shields Up) by nation-state
threats, including more DDSs attacks on websites and infrastructure. Most
ominous was the hacking of a Ukrainian satellite.
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 2/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
Cyber-Trends:
Forbes Daily: Get our best stories, exclusive reporting and essential analysis of
the day’s news in your inbox every weekday.
By signing up, you accept and agree to our Terms of Service (including the class action waiver and arbitration provisions), and
you acknowledge our Privacy Statement.
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 3/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
While AI and ML can be important tools for cyber-defense, they can also be a two
edged sword. While it can be used to rapidly identify threat anomalies and
enhance cyber defense capabilities, it can also be used by threat actors.
Adversarial Nations and criminal hackers are already using AI and MI as tools to
find and exploit vulnerabilities in threat detection models.
Cyber criminals are already using AI and machine learning tools to attack and
explore victims’ networks. Small business, organizations, and especially
healthcare institutions who cannot afford significant investments in defensive
emerging cybersecurity tech such as AI are the most vulnerable. Extortion by
hackers using ransomware and demanding payment by cryptocurrencies may
become and more persistent and evolving threat. The growth of the Internet of
Things will create many new targets for the bad guys to exploit. There is an
urgency for both industry and government to understand the implications of the
emerging morphing cyber threat tools that include AI and ML and fortify against
attacks.
Please also see the recent FORBES article discussing three key applications of
artificial intelligence for cybersecurity including, Network Vulnerability
Surveillance and Threat Detection, Incident Diagnosis and Response,
and applications for Cyber Threat Intelligence Reports: Three Key
Artificial Intelligence Applications For Cybersecurity by Chuck Brooks
and Dr. Frederic Lemieux Three Key Artificial Intelligence Applications For
Cybersecurity by Chuck Brooks and Dr. Frederic Lemieux (forbes.com)
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 4/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
A close-up on an abstract design of a display, which is warning about a cyber attack. Multiple rows ...
[+] GETTY
Programming code abstract technology background of software developer and Computer script GETTY
vulnerability data was included in Synopsys' 2023 Open Source Security and Risk
Analysis (OSSRA) report on 2022 data. Since most software applications rely on
open source code, this is still a significant cybersecurity issue to address.
The report noted: “open source was in nearly everything we examined this year; it
made up the majority of the code bases across industries,” the report said, adding
that the code bases contained troublingly high numbers of known vulnerabilities
that organizations had failed to patch, leaving them vulnerable to exploits. All
code bases examined from companies in the aerospace, aviation, automotive,
transportation, and logistics sectors contained some open source code, with open
source code making up 73% of total code. “
As significant as the risks from the open source code are, they can be detected by
penetration testing and especially by patching. The report found that patches
clearly are not being appplied. It cited that “of the 1,481 code bases examined by
the researchers that included risk assessments, 91% contained outdated versions
of open-source components, which means an update or patch was available but
had not been applied.”
Please see: At least one open source vulnerability found in 84% of code
bases: Report At least one open source vulnerability found in 84% of code
bases: Report | CSO Online
On way that hackers take advantage of code vulnerabilities and open source flaws
is via zero-day exploits. Recently a ransomware gang used a new zero-day flaw to
steal data on 1 million hospital patients. “Community Health Systems (CHS), one
of the largest healthcare providers in the United States with close to 80 hospitals
in 16 states, confirmed this week that criminal hackers accessed the personal and
protected health information of up to 1 million patients. The Tennessee-based
healthcare giant said in a filing with government regulators that the data breach
stems from its use of a popular file-transfer software called GoAnywhere MFT.”
Clop claims it mass-hacked 130 organizations, including a US hospital network
My Take: as a remedy to avoid vulnerability exploits and keep open source code
updated, the report suggested that organizations should use a Software Bill of
Materials (SBOMS) . I agree, in addition to Pen testing, SBOMS are an important
way to map systems and organize to be more cyber secure. An SBOM is basically a
list of ingredients that make up software components and serves as a formal
record containing the details and supply chain relationships of various
components used in building the software. I wrote about this extensively in a
previous FORBES article.
In the article, Dmitry Raidman. CTO, of a company called Cybeats offered insights
into l specific use cases for SBOMS. They include transparency into software
provenance and pedigrees, continuous security risk assessment, access control
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 6/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
and sharing with customer who can access and what data can be seen, threat
intelligence data correlation, software composition license analysis and policy
enforcement, software component end of life monitoring, SCRM - Supply Chain
Risk Management and supply chain screening, SBOM documents repository and
orchestration, efficiency in data query and retrieval.
Clearly, SBOMS are a good path forward in discovering and correcting open
source vulnerabilities in code. Please see: Bolstering Cybersecurity Risk
Management With SBOMS Bolstering Cybersecurity Risk Management With
SBOMS (forbes.com)
Phishing is still the tool of choice for many hackers. Phishing is commonly defined
as a technique of hackers to exfiltrate your valuable data, or to spread malware.
Anyone can be fooled by a targeted phish, especially when it appears to be coming
as a personal email from someone higher up the work chain, or from a bank,
organization, or a website you may frequent.
Advances in technology have made it easier for hackers to phish. They can use
readily available digital graphics, apply social engineering data, and a vast array of
phishing tools, including some automated by machine learning. Phishing is often
accompanied by ransomware and a tactic for hackers is to target leadership at
companies or organizations (spear-phishing) because they usually have better
access to valuable data and make ready targets because of lack of training.
According to the firm Lookout, the highest rate of mobile phishing in history was
observed in 2022, with half of the mobile phone owners worldwide exposed to a
phishing attack every quarter. The Lookout report was based on Lookout’s data
analytics from over 210 million devices, 175 million apps, and four million URLs
daily. The report noted that “non-email-based phishing attacks are also
proliferating, with vishing (voice phishing), smishing (SMS phishing), and
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 7/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
quishing (QR code phishing) increasing sevenfold in the second quarter of 2022.
And that “the damage can be colossal for businesses that fall victim to mobile
phishing attacks: Lookout calculated that the potential annual financial impact of
mobile phishing to an organization of 5000 employees is nearly $4m.
The report also noted that “Cybercriminals mostly abused Microsoft's brand name
in phishing attacks, with more than 30 million messages using its branding or
mentioning products like Office or OneDrive. However, other companies were
also frequently impersonated by cybercriminals, including Amazon (mentioned in
6.5 million attacks); DocuSign (3.5 million); Google (2.6 million); DHL (2
million); and Adobe (1.5 million).”
Please see: Record Number of Mobile Phishing Attacks in 2022 Record Number
of Mobile Phishing Attacks in 2022 - Infosecurity Magazine (infosecurity-
magazine.com)
3D rendering Glowing text Ransomware attack on Computer Chipset. spyware, malware, virus Trojan, ...
[+] GETTY
Currently, ransomware, mostly via phishing activities, is the top threat to both the
public and
private sectors. Ransomware allows hackers to hold computers and even entire
networks hostage for electronic cash payments. In the recent case of Colonial
Pipeline, a ransomware attack disrupted energy supplies across the east coast of
the United States.
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 8/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
My Take: Since most of us are now doing our work and personal errands on
smartphones, this is alarming data. But there are remedies. Training employees to
identify potential phishing emails is the first step in prevention, but many of the
obvious clues, such as misspelled words and poor grammar, are no longer
present. Fraudsters have grown more sophisticated, and employees need to keep
up with the new paradigm.
Human errors are inevitable, however, and some employees will make mistakes
and accidentally fall victim to phishing. The backup system at that point should
include automated systems that can silo employee access and reduce damage if a
worker’s account is compromised. The best way is to establish and monitor
administrative privileges for your company. You can limit employee access or
require two [authentication] steps before they go there. A lot of companies will
also outlaw certain sites that workers can’t go visit, so it makes it more difficult to
get phished.
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surface… 9/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
Creative abstract postal envelopes sketch on modern laptop background, e-mail and marketing concept. ...
[+] GETTY
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 10/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
leveraging collaboration tools beyond email that include chat and mobile
messaging — including popular cloud-based applications such as Slack,
WhatsApp, LinkedIn, Facebook, Twitter and many more — to carry out attacks.”
Please see: The evolution of business email compromise to business
communication compromise The evolution of business email compromise to
business communication compromise (betanews.com)
Fraud Alert in red keys on high-tech computer keyboard background with security engraved lock on ...
[+] GETTY
Fraud has always been a societal problem, but it is being compounded by the
expansion of criminals in the digital realm. The cost is going higher as more
people do their banking and buying online.
Federal Trade Commission (FTC) data shows that consumers reported losing
nearly $8.8 billion to fraud in 2022, an increase of more than 30 percent over the
previous year. Much of this fraud came from fake investing scams and imposter
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 11/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
scams. Perhaps most alarming in this report was that there were over 1.1 million
reports of identity theft received through the FTC’s IdentityTheft.gov website.
FTC reveals alarming increase in scam activity, costing consumers
billions - Help Net Security
My take: the reason for the increased rate of identity fraud is clear. As we become
more and more connected, the more visible and vulnerable we become to those
who want to hack our accounts and steal our identities. The surface threat
landscape has expanded exponentially with smartphones, wearables, and the
Internet of Things. Moreover, those mobile devices, social media applications,
laptops & notebooks are not easy to secure.
There are no complete remedies to identity theft but there are actions that can
enable people and companies to help deter the threats. Below is a quick list of
what you can to help protect your accounts, privacy, and reputation:
1) Use strong passwords. Hackers are quite adept at guessing passwords especially
when they have insights into where you lived in the past (street names), birthdays
and favorite phrases. Changing your password regularly can also complicate their
tasks.
3) Consider using encryption software for valuable data that needs to be secured.
Also set up Virtual Private Networks for an added layer of security when using
mobile smartphones.
4) Very important; monitor your credit scores, your bank statements, and your
social accounts on a regular basis. Life Lock and other reputable monitoring
organizations provide account alerts that are very helpful in that awareness quest.
The quicker you detect fraud the easier it is to handle the issues associated with
identity theft.
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 12/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
Business and technology concept. Internet of Things(IoT). Information Communication Network(ICT). ...
[+] GETTY
There is a very good report done by the Bipartisan Policy Research Center on the
top eight macro risks to watch out for in 2023. The are stated below from the
article and I agree with them all.
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 13/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
Please see: Cyber arms race, economic headwinds among top macro
cybersecurity risks for 2023 Cyber arms race, economic headwinds among
top macro cybersecurity risks for 2023 | CSO Online
And for a deeper dive on cyber stats please see: 34 cybersecurity statistics to
lose sleep over in 2023 34 cybersecurity statistics to lose sleep over in 2023
(techtarget.com) The article notes upfront that that we need understand the data
and its immense volume used for cyber-attacks. “By 2025, humanity's collective
data will reach 175 zettabytes — the number 175 followed by 21 zeros. This data
includes everything from streaming videos and dating apps to healthcare
databases. Securing all this data is vital.”
Please also see Dan Lohrman’s annual analysis on cybersecurity trends: “After a
year full of data breaches, ransomware attacks and real-world cyber impacts
stemming from Russia’s invasion of Ukraine, what’s next? Here’s part 1 of your
annual roundup of security industry forecasts for 2023 and beyond.” The Top 23
Security Predictions for 2023 (Part 1) The Top 23 Security Predictions for
2023 (Part 1) (govtech.com) and The Top 23 Security Predictions for 2023
(Part 2) The Top 23 Security Predictions for 2023 (Part 2) (govtech.com)
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 14/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
My Take: Of course, there are many other trends and statistics to explore as the
year unfolds. It is certainly a treacherous cyber ecosystem, and it is expanding
with risk and threats. Being cyber-aware is part of the process of risk management
and security and hopefully looking at the cyber-threat landscape will implore both
industry and government to prioritize cybersecurity from the top down and
bottom up!
Chuck Brooks is a globally recognized thought leader and subject matter expert
Cybersecurity and Emerging Technologies. Chuck is also an Adjunct Faculty at
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 15/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 16/17
6/15/23, 4:09 PM Cybersecurity Trends & Statistics For 2023; What You Need To Know
TECHCRUNCH
ADVERTISEMENT
https://www.forbes.com/sites/chuckbrooks/2023/03/05/cybersecurity-trends--statistics-for-2023-more-treachery-and-risk-ahead-as-attack-surfac… 17/17