This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Perception vs. Reality: Ransomware and BEC in the Cyber Threat Landscape

Download resources

About this session

Brynna Nery, cloud security architect at Abnormal Security, contrasts ransomware, the visible menace, with business email compromise, the silent one that costs more. Ransomware is driven by ransomware-as-a-service operators, extortion and cryptocurrency; it is industry-agnostic, targets mid-sized victims with a median revenue around 27 million, avoids Russia, and is centralised around a few groups such as LockBit and Conti, which makes it fragile when a group is dismantled. BEC reached 2.4 billion in reported losses in 2021, about 120,000 per attack and more than a third of all cybercrime losses, yet rarely counts as a reportable breach. She walks through a vendor email compromise chain: credential phishing, a hidden forwarding rule, weeks of silent observation, then a perfectly styled invoice from a trusted identity that bypasses signature-based gateways and awareness training. Comparing reported attacks (about 19,900 BEC versus 3,700 ransomware) and losses, she calls BEC the higher risk, predicts that crypto regulation, the war in Ukraine and law enforcement pressure will push ransomware skills toward BEC mule networks, and recommends identity-centric, cloud-integrated email defences and supply-chain awareness.

Colonial Pipeline. CNA Financial. Quanta. Even the NBA. Hardly a week goes by without a ransomware story hitting the news, as organizations worldwide are targeted by an attack.But are there more dangerous threats out there? Join us to hear Brynna Nery, Cloud Security Architect at Abnormal Security, discuss the real threats in today’s landscape, and why ransomware is only one of your concerns. She’ll answer questions like: • How has the cyber threat landscape changed over the past decade? • What drives threat actors to change their methods and tactics? • Why should stopping business email compromise be at the top of your priority list? • And what will change as new regulations are put in place? With full insight into the past, present, and future of the threat landscape, this presentation will provide you with everything you need to understand what could be targeting your organization.

Key takeaways

  • Budget defences by loss, not by headlines: reported BEC losses were roughly fifty times ransomware losses in the same year, with about five times as many incidents.
  • Watch for the vendor email compromise pattern (credential phishing, then a mailbox forwarding rule, then a well-timed invoice) and audit forwarding rules and payment-change requests with out-of-band verification.
  • Do not rely on signature-based gateways or generic awareness training against BEC; the emails come from real, trusted accounts with no classic phishing indicators.
  • Integrate email security directly with the cloud mail platform (Microsoft 365, Google Workspace) so behaviour and identity, not just payloads, are analysed.
  • Map your vendor ecosystem and its security maturity, since smaller suppliers below the security poverty line are the usual entry point for financial supply-chain fraud.

Speakers

Brynna Nery
Brynna Nery
Cloud Security Architect · Abnormal Security
Brynna Nery is a friendly Cloud Security Architect at Abnormal Security. She is passionate about collaborating to build security into "All the Things". She is also an active contributing member of the Cloud Security Alliance and content lead for the… Read moreRead less

Brynna Nery is a friendly Cloud Security Architect at Abnormal Security. She is passionate about collaborating to build security into "All the Things". She is also an active contributing member of the Cloud Security Alliance and content lead for the DevSecOps working groups and Cloud Key Management working group.

Resources

Tags

More from GoSec 2022

Also from Brynna Nery

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.