Rising Access of AI Powered Technology Enables Development of Malware
CIOREVIEW >> EAM >> NEWS

Home Capital Group Inc.

Sanja Cancar-Todorovic, Head of Enterprise Procurement, Outsourcing & Third-Party Risk Management

Rising Access of AI Powered Technology Enables Development of Malware

Sanja Cancar-Todorovic, Head of Enterprise Procurement, Outsourcing & Third-Party Risk Management
Sanja Cancar-Todorovic, Head of Enterprise Procurement, Outsourcing & Third-Party Risk Management, Home Capital Group Inc.

The World Economic Forum's Global Cybersecurity Outlook report indicates that cyberattacks increased 125 percent globally in 2021, with an expected continued uptick. And while cyber-security related issues are not new, what has changed in the recent years is a massive move to the Cloud, IoT, e-commerce, remote accesses and overall digital transformations.

The digital transformation that most organizations underwent since early 2020 was primely driven by (not the CIO) but COVID-19. The pandemic accelerated the fourth industrial revolution that most organizations were tip-toeing around, before pandemic pushed them into it.

But with massive changes, we are also exposed to massive risks, that if not mitigated could have catastrophic consequences. Every day we are witnessing more and more cyberattacks, data-breaches and privacy concerns. The rising access of AI powered technology that enables the development of malware, scripting and other tools, provide hackers with the ability to manufacture near perfect ways to execute on their plans, with very little effort. The ultimate goal: highly lucrative ransom. With our reliance on technology, the ransomware industry has grown into a multi-billion-dollar global criminal industry, with no indications of slowing down.

How do we mitigate this risk? Start by performing a detailed risk assessment to discover any systems or data that are vulnerable to a cyberattack and then work with experts to determine how to protect them. This will require investing in people, processes, and technologies, with cyber awareness training being at the forefront of the entire endeavour.

However, it is not enough just to have the strong controls in place within your own organization. You must take it one step further. Things like vendor concentration, fourth party risk management; information security, business continuity, vendor reputational risk, and vendor financial health are all now part of the elevated Third-Party Risk Management (TPRM) process that starts right at the vendor evaluation and onboarding stage. It is managed through structured well-defined Vendor Governance Process and Continuous Risk Monitoring.  

“The rising access of AI powered technology that enables the development of malware, scripting and other tools, provide hackers with the ability to manufacture near perfect ways to execute on their plans, with very little effort. The ultimate goal: highly lucrative ransom.”

Arguably, out of all of the TPRM components, Information Security requires the most attention, as it is the biggest threat to any organization. Your organization’s Information Security is only as good as your weakest IT vendor.

Fortunately, there are many InfoSec tools available to continually monitor vendor risk profiles based on data breaches and/or cyber attacks. However, by the time you are notified of them, it might already be too late. The best defense remains comprehensive vendor due diligence process, including reviews of the independent InfoSec Audits and vendor SOC reports, by the organization’s IT subject matter experts. This should never be one time event at the onboarding stage, but rather an annual process performed by your organization for every critical vendor that has any ability to impact your IT infrastructure.

Additionally, there should be, at a minimum, quarterly reviews of all critical vendors with the low or fluctuating risk profiles, followed by the detailed analysis of their scores and the reasons behind them. This type of review will ensure that all the right people at your organization are aware of potential risks, but also are in the position to challenge the scoring. Some vendors risk profile may be impacted by things such as IaaS shared responsibility models they have with other customers, or even nature of their business (eg. ISP). And while the InfoSec tools will show this as risk, a detailed quarterly review by your organization can segment it out since it does not represent a significant security risk to your organization.

This approach also creates an opportunity for organizations to collaboratively work with their IT vendors to protect each other. By sharing their own risk profiles with your vendors, and working together to address any gaps, you are investing in the stronger security for both organizations. This further creates an opportunity, to exchange best practices, new ideas and lessons learnt between both parties. It is time very well spent, and ensures strong strategic partnerships between the two companies.

Nevertheless, even if all the due diligence checks out, at the onboarding and the annual assessment phase, and even if the quarterly internal assessments show no serious security risks, all organizations should have a well-established and documented exit strategy for each of their critical IT vendors. This practice will force the organization to really think about their relationship with their IT vendors, avoid concentrating massive scope to one vendor, and remove sole sourcing practices all together.

The question is not if an attack happens, but rather when an attack happens. Anyone can get hacked at any time, inadvertently making the entire organization vulnerable. While some cyber attacks are targeted, some of them are done using scattergun approach, sending phishing emails to thousands of potential victims with a link or an attachment, that when opened infects the system and creates widespread problem. Depending on the nature of the attack and the information that is compromised, organizations might not only have their customer base impacted, resulting in financial loss and tarnished reputation, but can also be subject to regulatory fines and penalties.

As cyber attacks become more sophisticated, our defence also needs to become more sophisticated. Failing to plan is planning to fail, and with the ever-increasing reliance on IT, organizations cannot afford not to be over-prepared.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.