Cybercrime economy revealed by Hewlett Packard Enterprise

Hewlett Packard Enterprise has published “The Business of Hacking”, a comprehensive report that analyzes in detail the economy behind cybercrime.

Follow FullPress on Google

Add us to your preferred sources.

Follow this source on Google

The study provides an in-depth analysis of the motivations behind attacks launched by cybercriminals, as well as the ‘value chain’ created by illegal organizations to extend their reach and maximize profits. Based on this information, the report offers useful suggestions for mitigating risks and hindering these criminal groups.

The profile of the cybercriminal and the interconnected nature of the underground economy they are part of have evolved enormously in recent years. Increasingly, hackers adopt sophisticated

The cybercriminal value chain

Today’s cybercriminals often use a formal operating model and a ‘value chain’ that is structurally very similar to those of normal companies and capable of ensuring a higher ROI throughout the life cycle of an attack. Company security managers, legislators, and law enforcement agencies intending to stop cybercriminals must first understand all the elements that make up the value chain of this underground economy. 

The critical elements of cybercriminal value chain models usually include:

  • Human resources management – recruitment, selection, and remuneration of the support staff needed to carry out specific attacks; training and education also fall under this area.
  • Operations– management team that ensures the regular flow of information and funds throughout the life cycle of an attack, and is actively engaged in reducing costs and maximizing ROI at every stage of the process.
  • Technical development – the front line that has all the technical skills necessary to perpetrate any attack, taking on research, vulnerability exploitation, and automation activities, etc.
  • Marketing and sales – teams committed to ensuring that the cybercriminal group’s reputation is strong and perceived in the underground market, and that their products are considered reliable by potential buyers.
  • Outbound logistics – people and systems responsible for delivering purchased goods to the customer, whether they are large volumes of credit card data, medical records, intellectual property, or anything else.

Disrupting the chain and strengthening corporate protection

HPE proposes several approaches through which corporate security professionals can better defend themselves from these criminal organizations:

  • Reduce their profits – limit the financial revenue that hackers can achieve by attacking a company, thanks to end-to-end cryptographic encryption solutions, such as HPE SecureData. By encrypting data at rest, in transit, and in use, the information becomes completely unusable for cybercriminals, as it limits their ability to resell it and therefore to profit from it.
  • Reduce the attack surface – the proliferation of IoT and mobile devices has enormously expanded potential attack areas, so all types of organizations must necessarily integrate security into their development processes to protect interactions between data, apps, and users, regardless of the device; as well as mitigate and hinder attacks.
  • Learn from adversaries – new technologies, such as, for example, so-called ‘deception grids’, offer methods to trap and monitor cybercriminals as they move within a realistic duplicate of the network, thus learning from their actions. Companies can then use the information obtained in this way to better protect their networks, block similar attacks before they can even begin, and slow down their development. 

Accompanying video, infographic, and webinar

  • Webcast: opportunity to register for the webcast that will be broadcast on June 14th at 7:00 PM Italian time. HPE Security and Chris Christiansen, an IDC industry expert, will focus on actions taken by organizations to protect themselves from cybercriminals, the evolution of security, and future developments.
  • Webcast: Cybercriminals – The unaddressed competition. Here’s how HPE is studying the world of cybercriminals to understand and hinder them more effectively.

Methodology

The “Business of Hacking” report uses data and observations from HPE Security teams, open-source intelligence, and other industry reports to provide insights into the motivations that drive cybercriminals, their organizations, and the existing opportunities that companies can leverage to better hinder such activities and mitigate risks.

Pubblicato in

Se vuoi rimanere aggiornato su Cybercrime economy revealed by Hewlett Packard Enterprise iscriviti alla nostra newsletter settimanale

Be the first to comment

Leave a Reply

Your email address will not be published.


*