Connect with us
https://tickernews.co/wp-content/uploads/2023/10/AmEx-Thought-Leaders.jpg

Tech

Cybercrime insurance is making the ransomware problem worse

Published

on

Cybercrime insurance is making the ransomware problem worse.

During the COVID-19 pandemic, there was another outbreak in cyberspace: a digital epidemic driven by ransomware.

Several organisations worldwide fell victim to cyber-extortionists who stole data either to sell to other criminals or held it as a ransom for a profit. The sheer number of attacks indicates that cyber security and anti-ransomware defences did not work or have limited effectiveness.

Businesses are turning to cyberinsurance companies in desperation to protect themselves from attack. But the growth of the cyberinsurance market is only encouraging criminals to target companies that have extortion insurance.

A 2021 study from the University of Leeds found there was a massive acceleration in major cyber-attacks on organisations during the pandemic. The paper also showed a “shift in offender tactics which scale up levels of fear in victims … such tactics include a shift towards naming and shaming victims, the theft of commercially sensitive data and attacks targeting organisations which provide services to other organisations.”

A report by global cybersecurity firm Sophos found that 66% of organisations surveyed, from across 31 countries, were hit with ransomware in 2021, up from 37% in 2020. The average ransom paid increased nearly fivefold to US$812,360 (£706,854). Insurance companies often opt to pay the ransoms that cybercriminals demand – 82% of UK companies pay up.

According to US think tank the Council on Foreign Relations 22 countries are suspected of sponsoring cyberattacks, including the United States.

And a new black market in which cybercriminals provide products and services to other cybercriminals is flourishing and driving the surge in ransomware attacks. So-called ransomware allows everyone from teenagers to skilled amateurs to professional criminals to rent malware, encryption tools, and even Bitcoin wallets.

It is like a criminal renting a gun from another criminal who manufactured it.

In July 2020, three teenagers hacked Twitter. The attack resulted in the hijacking of 130 accounts – some of which included high-profile targets including Joe Biden, Barack Obama, Apple, Elon Musk and Bill Gates. The bitcoin accounts associated with their ransomware scam received more than 400 transfers totalling over US$100,000 (£87,000).

The past few years have seen a surge in specialist cybercrime insurance policies. The global cybercrime insurance market is predicted to grow from US$7 billion in gross written premiums (GWP) in 2020 to US$20.6 billion by 2025.

Insurers need to do more to discourage incompetent security practices. Car drivers must pass theory and practical driving tests. But cyberinsurance policies rarely audit the IT security of an organisation before the policy is finalised.

A standardised ISO norm (quality management standards internationally agreed by experts) for software did not exist until 2015. It means customers have no way of judging the security standards of anything produced before 2015. Even now, some of the risk assessments a software would go through in its lifetime could be less rigorous than for the kettle in our home. And ISO testing is voluntary.

The market lacks understanding of large-scale, sophisticated, cyber-attacks. The insurance sector works by determining the probability of an incident happening and the impact it would have. The cyberinsurance market struggles to forecast the likelihood of cyber-attacks because changes in digital technology can be so unpredictable. Attackers’ capabilities and intentions shift rapidly.

Most insurers currently have no long-term data for cyberincidents or ransomware. This has led to underfunded cyberinsurance programs, which rely heavily on optimistic financial models.

As a result it is getting more difficult to secure cyberinsurance as the growing number of claims is forcing valuers to be more discerning in the clients they accept. Lloyds of London released new rules in December 2021 stating that underwriters will no longer cover damage caused by “war or a cyberoperation that is carried out in the course of the war”.

Insurance premiums increased by 22% in 2020 and a further 32% in 2021 across 38 countries. The cost incurred by the business gets passed on to customers. The ransomware demand will contribute to the overall rise in living costs as ransomware costs are being passed on to the customers.

As part of my work with the Northern Cloud Crime Centre, I looked at the effectiveness of laws in the UK to regulate criminal activity in the Cloud. I found the cybercrime legislation in the UK has failed to keep pace with technological and market developments over the past 30 years. The Computer Misuse Act 1990 needs updating to make it more effective at policing cybercrime. If we cannot fix the situation, it will threaten jobs and investment in the UK.

Ransomware attacks are so effective because they exploit human weaknesses and organisations’ lack of technological defences.

Law enforcement authorities advise ransomware victims not to pay the ransom because it encourages further attacks and fuels a vicious cycle.

But prevention is the best solution. Organisations need to put more effort into developing security measures such as a multifactor authentication system. Managers also need to carry out penetration testing, where a cybersecurity expert searches for vulnerabilities in a computer system.

Businesses are legally obliged to have a fire plan in place. The time has come formandatory ransomware and phishing resilience testing. The insurance industry needs to set minimum security requirements as part of the risk assessment. Organisations need greater transparency regarding what security they do and do not have in place.

Consensus is growing among researchers that solid cybersecurity can’t be achieved with technology alone because a human errors are to blame for a huge amount of incidents. The UK government is proposing new laws to regulate cybersecurity standards. But these laws won’t work if it doesn’t invest in public education about phishing threats.

Cybercrime insurance can help minimise business disruption, provide financial protection, and even help with legal and regulatory actions after a cyberincident. But it will not solve the problems that created the vulnerability to an attack in the first place.

Disclaimer: This asset – including all text, audio and imagery – is provided by The Conversation. Ticker News does not guarantee the accuracy of, or endorse any views or opinions expressed in, this asset.

Continue Reading

Tech

Airbus A320 fleet faces software upgrade due to risk

Airbus alerts A320 operators to urgent software fix after JetBlue incident raises safety concerns

Published

on

Airbus alerts A320 operators to urgent software fix after JetBlue incident raises safety concerns

video
play-sharp-fill
In Short:
– Airbus warns over half of A320 fleet needs software fixes due to potential data corruption risks.
– Affected airlines must complete upgrades before next flights, with operational disruptions anticipated during a busy travel season.

Airbus has issued a warning regarding its A320 fleet, indicating that over half of the active jets will require a software fix.

It follows a recent incident involving a JetBlue Airways aircraft, where “intense solar radiation” was found to potentially corrupt data crucial for flight control system operation.

The European plane manufacturer stated that around 6,500 jets may be affected. A regulation mandates that the software upgrade must occur before the next scheduled flight.

Banner

Operational disruptions for both passengers and airlines are anticipated. The issue arose from an incident on October 30, where a JetBlue flight experienced a computer malfunction that resulted in an uncommanded descent. Fortunately, no injuries occurred, but the malfunction of an automated computer system was identified as a contributing factor.

Airlines, including American Airlines Group, have begun to implement the required upgrades.

The majority of affected jets can receive an uncomplicated software update, although around 1,000 older models will necessitate an actual hardware upgrade, requiring grounding during maintenance.

Hungarian airline Wizz Air has also initiated necessary maintenance for compliance, potentially affecting flights. This announcement has surfaced during a busy travel season in the US, with many facing delays due to other factors as well.

Regulatory Response

The European Union Aviation Safety Agency has mandated that A320 operators replace or modify specific elevator-aileron computers. The directive follows the JetBlue incident, where a malfunction led to a temporary loss of altitude.

Airbus’s fix applies to both the A320 and A320neo models, representing a vital response in ensuring aircraft safety.


Download the Ticker app

Continue Reading

Tech

China blocks ByteDance from using Nvidia chips in new data centres

China blocks ByteDance from using Nvidia chips, tightening tech control and pushing for domestic AI innovation amid U.S. restrictions.

Published

on

China blocks ByteDance from using Nvidia chips, tightening tech control and pushing for domestic AI innovation amid U.S. restrictions.


Chinese regulators have moved to block ByteDance from deploying Nvidia chips in newly built data centres, tightening control over foreign technology used by major Chinese tech giants. The decision comes after ByteDance made substantial purchases of Nvidia hardware amid fears of shrinking supply from the United States.

Washington has already restricted the sale of advanced chips to China, allowing only weakened versions into the market. Beijing’s latest move reflects its push to reduce dependence on U.S. technology and accelerate home-grown AI innovation.

The ban places operational and financial pressure on ByteDance, which must now work around a growing pile of Nvidia chips it is no longer allowed to use. Domestic suppliers like Huawei are expected to step in as China intensifies its pursuit of tech self-reliance.
Subscribe to never miss an episode of Ticker – https://www.youtube.com/@weareticker

#ChinaTech #ByteDance #Nvidia #AIIndustry #USChinaTech #ChipRestrictions #Huawei #TechPolicy


Download the Ticker app

Continue Reading

Tech

OpenAI launches shopping research tool for ChatGPT users

OpenAI launches shopping research tool to enhance e-commerce experience ahead of holiday season spending boost

Published

on

OpenAI launches shopping research tool to enhance e-commerce experience ahead of holiday season spending boost

video
play-sharp-fill
In Short:
– OpenAI’s “shopping research” tool helps users find detailed shopping guides tailored to their preferences.
– Users can access Instant Checkout for purchases while ensuring user chats are not shared with retailers.
OpenAI has launched a new tool called “shopping research,” coinciding with an increase in consumer spending ahead of the holiday season.This tool is aimed at ChatGPT users seeking comprehensive shopping guides that detail top products, key differences, and the latest retailer information.

Users can customise their guides based on budget, features, and recipients. OpenAI notes that while the tool takes a few minutes to generate responses, users can still use ChatGPT for quicker queries like price checks.

Banner

When users ask specific prompts, such as finding a quiet cordless stick vacuum or a gift for a niece who loves art, the shopping research tool will appear automatically. It can also be accessed via the menu.

Shopping Research

OpenAI has been expanding its e-commerce capabilities, with the introduction of the Instant Checkout feature in September, enabling purchases directly through ChatGPT.

Soon, users of the shopping research tool will also be able to use Instant Checkout for making purchases.

OpenAI assures that shopping research results are derived from publicly available retail websites and will not disclose user chats to retailers, although it does warn that inaccuracies may occur in product availability and pricing.

Shopping research is now available to OpenAI’s Free, Go, Plus, and Pro users logged into ChatGPT.


Download the Ticker app

Continue Reading

Trending Now