Sophos Says India Has Talent, Tools Yet Can't Tackle Big Cyber-Attacks

Advertisement
By Indo-Asian News Service | Updated: 3 October 2017 18:03 IST
Highlights
  • Despite having talent and resources, India fails to curb some cybercrimes
  • Sophos' Shier shared India has well-trained, educated IT fraternity
  • Few Indian firms were recently affected by WannaCry, Petya ransomwares

India has a talented workforce and access to all the tools to safeguard its systems against data breaches, yet the country is unprepared to handle a massive cyber-attack like 'WannaCrypt' or 'Petya,' a top executive from global IT security firm Sophos has said.

"India has well-trained, well-educated and capable IT people. The country has got access to all the tools it needs to secure its systems. Yet, in the case of a big cyber-attack, India is still unprepared," John Shier, Senior Security Expert at the Abingdon, UK-headquartered Sophos, told IANS in an interview.

Advertisement

"It is the time to look at the procedures and make sure they are implemented to secure the data. Firstly, it is needed to see that the things are done. Secondly, it needs to be checked if the things are done correctly and thirdly, test it repeatedly to makes sure what has been done is done right," Shier noted.

According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 saw a 10 percent decline globally when compared to 2016, for the Indian enterprises, it grew 12.3 percent from Rs. 97.3 million in 2016 to Rs. 110 million in 2017.

Advertisement

Malicious or criminal attacks were the cause of data breach for 41 percent of companies surveyed. Nearly 33 percent experienced a data breach as a result of system glitches and 26 percent breaches involved employee or contractor negligence.

According to Shier, while you cannot entirely eliminate cyber risks, you can reduce it to a very low level if you have well-configured security measures to check the intrusion.

Advertisement

"The systems that are being compromised by cyber-attackers are owing to the poor security of the system itself or the protections around it," he said.

The systems are generally protected by software and firewalls to restrict the intrusion.

Advertisement

"Companies have the necessary attack deterrents but they forget to configure them in certain ways to block the attack, resulting in improperly-secured devices," Shier explained.

He said that most companies are securing their data with security software and hardware in a correct manner but it is the human factor that, at times, makes cyber-attacks a success.

"Sometimes, the criminals send an email to an employee who acts upon it. That gives the cyber attackers the first foothold in the company and from there, the criminals are able to move around the systems in the company," the executive pointed out.

Shier said that most of the times, humans are very carefully intertwined in a cyber-attack.

"Since the unwanted entry is blocked, criminals steal authorised credentials of employees by sending them emails who act upon it. In this way, the criminal who was blocked from entering the system illegally, has legal access to a company's system," he noted.

Our lackadaisical approach also makes us vulnerable to data hacking.

"In the WannaCrypt ransomware attack case, systems were compromised due to a missing patch. The patch was already available two months before the cyber-attack happened," Shier said.

Hackers normally use the loopholes present in the security system.

"Cybercriminals find weak spot to get into the systems. It is not necessary that these criminals send an emaill; it might be a phone call or a physical visit to the company. They might visit the office for reconnaissance. They carry a ladder or a clipboard and pose as a worker," Shier told IANS.

Hackers build a "crack" around the protective measure and come up with new tactics to enter into systems but companies today are fairly well prepared for the attack.

"If we are well prepared for the attacks with fully functional and well-tuned security layers, then we can deflect a lot of attacks. Doing the basics right helps cyber-security companies stay one step ahead of the criminals," Shier said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto G37 Power Review: Covers All the Bases and More
  1. Nothing Ear 3a, CMF Buds Neo Spotted on Regulatory Databases Ahead of Anticipated Debut
  2. Samsung Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra Could Feature Vastly Different Designs, Leaked Dummy Units Suggest
  3. Hisense U7SE 144Hz ULED Mini-LED TV Series With Up to 100-Inch Screens Launched in India: Price, Features
  4. Vivo Y500 Surfaces on Bluetooth SIG Database With Multiple Model Numbers, Could Launch Soon
  5. Asus Ascent QN10 Mini PC With Snapdragon X2 Elite Chipset Showcased at Computex 2026
  6. MSI Showcases New Katana, Venture Laptops and Crosshair A16 HX MLG Edition at Computex 2026
  7. Acer TravelMate P6 14 AI and P2 Spin 14 Unveiled, Acer TravelMate X2 15 and X2 14 Tag Along
  8. Sony Bravia 7II 4K TVs Launched in India With Cognitive Processor XR, Dolby Vision: Price, Features
  9. Asus TUF 16 (2026) Gaming Laptop Unveiled Alongside ExpertBook B5 Flip G2 (2026) at Computex 2026
  10. Asus Zenbook 14, Vivobook S14, Vivobook S16, Vivobook S14 Flip and Vivobook S16 Flip Launched at Computex 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.