Sophos Says India Has Talent, Tools Yet Can't Tackle Big Cyber-Attacks

Advertisement
By Indo-Asian News Service | Updated: 3 October 2017 18:03 IST
Highlights
  • Despite having talent and resources, India fails to curb some cybercrimes
  • Sophos' Shier shared India has well-trained, educated IT fraternity
  • Few Indian firms were recently affected by WannaCry, Petya ransomwares

India has a talented workforce and access to all the tools to safeguard its systems against data breaches, yet the country is unprepared to handle a massive cyber-attack like 'WannaCrypt' or 'Petya,' a top executive from global IT security firm Sophos has said.

"India has well-trained, well-educated and capable IT people. The country has got access to all the tools it needs to secure its systems. Yet, in the case of a big cyber-attack, India is still unprepared," John Shier, Senior Security Expert at the Abingdon, UK-headquartered Sophos, told IANS in an interview.

"It is the time to look at the procedures and make sure they are implemented to secure the data. Firstly, it is needed to see that the things are done. Secondly, it needs to be checked if the things are done correctly and thirdly, test it repeatedly to makes sure what has been done is done right," Shier noted.

Advertisement

According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 saw a 10 percent decline globally when compared to 2016, for the Indian enterprises, it grew 12.3 percent from Rs. 97.3 million in 2016 to Rs. 110 million in 2017.

Advertisement

Malicious or criminal attacks were the cause of data breach for 41 percent of companies surveyed. Nearly 33 percent experienced a data breach as a result of system glitches and 26 percent breaches involved employee or contractor negligence.

According to Shier, while you cannot entirely eliminate cyber risks, you can reduce it to a very low level if you have well-configured security measures to check the intrusion.

Advertisement

"The systems that are being compromised by cyber-attackers are owing to the poor security of the system itself or the protections around it," he said.

The systems are generally protected by software and firewalls to restrict the intrusion.

Advertisement

"Companies have the necessary attack deterrents but they forget to configure them in certain ways to block the attack, resulting in improperly-secured devices," Shier explained.

He said that most companies are securing their data with security software and hardware in a correct manner but it is the human factor that, at times, makes cyber-attacks a success.

"Sometimes, the criminals send an email to an employee who acts upon it. That gives the cyber attackers the first foothold in the company and from there, the criminals are able to move around the systems in the company," the executive pointed out.

Shier said that most of the times, humans are very carefully intertwined in a cyber-attack.

"Since the unwanted entry is blocked, criminals steal authorised credentials of employees by sending them emails who act upon it. In this way, the criminal who was blocked from entering the system illegally, has legal access to a company's system," he noted.

Our lackadaisical approach also makes us vulnerable to data hacking.

"In the WannaCrypt ransomware attack case, systems were compromised due to a missing patch. The patch was already available two months before the cyber-attack happened," Shier said.

Hackers normally use the loopholes present in the security system.

"Cybercriminals find weak spot to get into the systems. It is not necessary that these criminals send an emaill; it might be a phone call or a physical visit to the company. They might visit the office for reconnaissance. They carry a ladder or a clipboard and pose as a worker," Shier told IANS.

Hackers build a "crack" around the protective measure and come up with new tactics to enter into systems but companies today are fairly well prepared for the attack.

"If we are well prepared for the attacks with fully functional and well-tuned security layers, then we can deflect a lot of attacks. Doing the basics right helps cyber-security companies stay one step ahead of the criminals," Shier said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Ajay Devgn-Starring De De Pyaar De 2 Could Arrive on OTT Next Year
  2. Vivo X300 Series India Launch Date Announced
  1. Coming-of-Age Web Series CO-ED to Stream on OTT Soon: Know When, Where to Watch Online
  2. Leonardo DiCaprio’s One Battle After Another Now Available for Rent on Prime Video: All You Need to Know
  3. Ajay Devgn's De De Pyaar De 2 OTT Debut Timeline Tipped: All You Need to Know
  4. Pradeep Ranganathan's Dude Now Streaming on OTT: Know All About This Tamil-Language Rom-Com Film
  5. Tim Cook to Reportedly Step Down as Apple CEO in 2026; Successor to Be Announced After January
  6. Vivo X300 Series India Launch Date Announced: Here's What to Expect
  7. Redmi Note 15 Series India Launch Timeline Tipped; Redmi 15C Could Debut This Month
  8. Poco Pad M1 May Come With Snapdragon 7s Gen 4 Chip and 12,000mAh Battery; Price Tipped
  9. BSNL Announces Silver Jubilee Prepaid Recharge Plan With 2.5GB of Daily Data and More Benefits
  10. Blue Origin Joins SpaceX in Orbital Booster Reuse Era With New Glenn’s Successful Launch and Landing
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.