Tuesday, June 24, 2025
  • Home
  • About us
  • Privacy policy
  • Advertise with us
  • Contact us
Fii News Logo
No Result
View All Result
  • Tenders
  • Projects
  • Markets
  • Manufacturing
  • Investment
  • Technology
  • Exports
Newsletter
  • Tenders
  • Projects
  • Markets
  • Manufacturing
  • Investment
  • Technology
  • Exports
Fiinews
No Result
View All Result
Home Investment

India suffered more than $15bn loss from cybercrime

Fiinews by Fiinews
November 18, 2020
in Investment, Technology
Reading Time: 4 mins read
A A
0
Cyble
0
SHARES
10
VIEWS
LinkedinShare on Twitter

0:00

Cybercriminals’ state-sponsored attacks on government agencies

India suffered more than US$15 billion due to cybercrime, cyber fraud, and identity theft in 2019 compared to the US$9.3 billion investment secured during the year.

What is gravely concerning is that while these are publicly affirmed numbers, the reality could be much worse, warned Cyble which has observed a significant uptick in cybercriminal activities, including a number of threat actors actively targeting the nation in the last 12 months.

The motives of cybercriminals range from state-sponsored attacks on government agencies to organized cybercriminals syphoning off confidential data or sensitive user information from businesses.

Here’s why Indian companies are turning into soft targets of cybercriminals, cautioned Cyble in a report on 17 Nov 2020.

•  Volume matters: India has one of the top 10 highest Internet users in the world. From students to government officials, most individuals are using Z-generation apps whether it is for making digital payments, paying mortgages, online banking, purchasing groceries, etc.

•  Inadequate regulatory framework: The data privacy and regulatory frameworks are significantly weaker and still in their infancy as compared with most other nations where laws are considerably matured and well in their implementation process. Presently, companies in India are not required to notify a breach by any mandate, thereby often leaving room for autonomy on the security measures around the data they are collecting. The impact of this is even magnified when the data pertains to personal information (PI) for a sizeable group of individuals.

•  Virtually Nonexistent Security Contact: Companies that have been a victim of cybercrime almost always have one thing in common – they do not have a designated CISO in place. Interestingly, organizations often enlist the help of the existing internal IT professionals for managing enterprise security issues. However, these individuals may not possess the requisite experience for performing a risk assessment and implementing strategic measures to combat the threat. They may also be burdened with bandwidth issues alongside inexperience on the security domain.

•  Poor Technical Measures: Factors such as the insufficient understanding of the need for an effective information security program coupled with inadequate attention towards a basic security hygiene have fostered malicious cyber activities.

“Most victims have a few common attributes such as a non-existent security awareness culture; Cloud Access Tokens that haven’t been changed for months and in some cases, for years; developers embedding credentials in their code repositories; and compromises due to phishing campaigns and credential stuffing,” said Cyble CEO Beenu Arora.

“Such lapses in the defense infrastructure are fueling the issues further,” he warned.

At an individual user lever, one of the most common security shortcomings is that of reusing the same login credentials and passwords across multiple sites or apps. This is one of the primary reasons for Credential stuffing. Considered one of the most common types of cyberattacks, Credential stuffing is the theft and misuse of login credentials, typically comprising usernames and email addresses and their corresponding passwords to gain unauthorized access to user accounts. Lately, credential stuffing has emerged as more prominent due to a rise in the number of high-profile breaches.

•  Lack of Accountability: Recent incidents have highlighted that organizations are yet to take cybersecurity issues seriously and give it due importance as part of their corporate social responsibility. Upon analyzing several high-profile breaches, Cyble noted that the diversity of personal information collected by organizations after a breach is considerably distressing. Corporations need to take stock of the grim reality of the cybersecurity space and acknowledge that adequate disclosure is the right move towards establishing customer trust and confidence in the long run.

This brings us to the question of where the company is heading. Public reports have clearly stated that India is an attractive target for cybercriminals for a host of reasons ranging from motives of financial gain to geopolitical agendas. Here are five essential things Cyble recommends technology-based companies to consider.

•  Appoint a CISO – Without a clear vision and accountability on protecting customers’ information and intellectual property, it would be a nightmare to manage the risks posed by the ever-evolving threat landscape.

•  Implement a Basic Security Hygiene – The Australian Signal Directorate has released strategies to mitigate cybersecurity incidents. In Cyble’s opinion, The Essential Eight, when implemented and governed correctly, can help thwart the majority of the cyberattacks.

•  Bolster Security Awareness Initiatives – Over 80% of cyberattacks originate via phishing and water-holing attacks. Organizations are increasingly using SSO to connect to their code repositories or third-party apps. Once a privileged account is compromised, the attacks can gain access to a large part of the company’s infrastructure, including customer records. Irrespective of how secure an enterprise’s IT security structure is, the company is only as protected as its user base. To improve awareness about phishing, organizations should conduct routine tests on the employees with fake phishing emails to educate them and help them learn how to recognize a real phishing attack.

•  Implement multi-factor authentication where possible. Ensure access token and secret keys are changed and accounted for regularly. This builds an additional layer of security for protecting highly sensitive user-PI.

•  Implement Robust Security Monitoring capabilities – As the landscape of an organization evolves, it is prudent to maintain situational awareness of the threats, risks, and vulnerabilities. #cybercrime #technologies #internet #online #economy #security #data /fiinews.com

Tags: Cyble
ShareTweetShare

Related Posts

Intellipaat Logo
Technology

Tech: Intellipaat integrates Agentic AI

by Fiinews
June 23, 2025
0
13

DevOps is evolving, says Chittora Intellipaat, a global leader in professional upskilling, has launched a groundbreaking transformation of its flagship...

India Ai
Technology

Tech: Vexoo Labs builds factual AI for MSMEs

by Fiinews
June 23, 2025
0
14

Most AI tools are built for showcase, says Kumar As hallucination-prone models dominate headlines, a homegrown deep-tech company Vexoo Labs...

Justenergy

Tech: HCLTech to enhance operations at Just Energy

June 23, 2025
14
Campus Fund

Invest: Campus Fund backs first-time founders

June 23, 2025
15
Ltimindtree Eurobank

Tech: LTIMindtree launches AI ecosystem

June 21, 2025
13
Sonatype

Tech: Sonatype opens Hyderabad centre to scale AI

June 21, 2025
15
SBI YONO

POPULAR NEWS

  • Cristina Dnv

    Projects: Indian yards set to build green ships, says DNV expert

    0 shares
    Share 0 Tweet 0
  • Market: Indian-origin UGF scales heritage consumer brands globally

    0 shares
    Share 0 Tweet 0
  • Technologies: Royal Diamond sponsors aerspace Industries’ drones in UAE

    0 shares
    Share 0 Tweet 0
  • Investments: Foreign investors see India as long-term destination for fund placings

    0 shares
    Share 0 Tweet 0
  • Markets: Blue Dart maintains positive outlook on India

    0 shares
    Share 0 Tweet 0

Fiinews.com features through news articles on business opportunities in the Indian market for the benefits of foreigners. It is also a platform for international businesses to showcase through elaborate articles on their products & services to the Indian consumers and corporations exploiting industrialisation of the country.

7Clicks Media is a Singapore based Media & PR company offering over 100,000
impressions via our targeted communication strategy.

It is led by editor-in-chief Gurdip Singh who has worked over 45 years reporting on
Asian businesses.

Recent News

  • Tender: SECI calls for Green Ammonia bids
  • Manufacturing: Dahod factory bid clarified
  • Tech: Intellipaat integrates Agentic AI
  • Tender: Kings Infra welcomes RBI Rs.10 lcr credit
  • Tech: Vexoo Labs builds factual AI for MSMEs

Pages

  • About US
  • ADVERTISE ON FIINEWS.COM
  • CONTACT US
  • EVENTS
  • FII-NEWS.COM PDF ARCHIVE
  • Home
  • News
  • PRIVACY POLICY

Subscribe to Newsletter

  • About
  • Advertise
  • Careers
  • Contact us

© 2024 FIINEWS - Design and developed by 7clicksmedia.

No Result
View All Result
  • Tenders
  • Projects
  • Markets
  • Manufacturing
  • Investment
  • Technology
  • Exports

© 2024 FIINEWS - Design and developed by 7clicksmedia.