News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
Business of Tech | Rising Costs of Cybersecurity: Average Attack Response Exceeds $5 Million

Microsoft wasn’t alone in being targeted by the SolarWinds hackers.   Hewlett Packard Enterprise (HPE) has disclosed that suspected Russian hackers known as Midnight Blizzard breached their Microsoft Office 365 email environment, gaining access to data from their cybersecurity team and other departments. The breach is believed to be related to a previous breach in May 2023, and HPE is working with external cybersecurity experts and law enforcement to investigate the incident. HPE has filed a form 8-K with the Securities & Exchange Commission to notify about the breach, but there has been no operational impact on their business.

AI startup Anthropic confirms a data leak caused by human error, where a contractor inadvertently sent a file containing non-sensitive customer information to a third party. The leaked information included a subset of customer names and open credit balances. Anthropic states that the breach was isolated and unrelated to an ongoing FTC probe. Customers are advised to be cautious of suspicious communications while the company provides support. The leak raises concerns about proprietary data security when using third-party language models. Anthropic’s relationships with AWS and Google are under scrutiny by regulators.

A report by Barracuda Networks reveals that the average cost of responding to cyber attacks exceeded $5 million in 2023, with an average attack cost of $2.98 million. Forced system downtime and availability problems resulted in an average revenue loss of $2.36 million. Additionally, the report highlights that it takes hackers approximately six hours to exploit a vulnerability, while IT security teams require 427 hours to investigate and address a successful phishing attack.

The number of ransomware victims paying ransom demands has dropped to a record low of 29% in the final quarter of 2023. This trend is attributed to better preparedness by organizations, lack of trust towards cybercriminals, and legal pressure against paying ransoms. The dollar amounts of ransom payments have also decreased, with an average of $568,705 and a median of $200,000 in Q4 2023.

The FBI has issued a warning about tech support scams using couriers to collect money and valuables from victims. Scammers impersonate tech support workers, government officials, technology companies, or financial institution employees to convince victims to liquidate their assets. Victims are coerced into converting their assets into cash or precious metals, which couriers then collect. The FBI advises individuals to be cautious and not send valuables to unknown individuals or share personal information. Victims are urged to report scams to the FBI and provide as much information as possible.

A team of security researchers has discovered a flaw in Microsoft’s Azure Pipelines that could allow hackers to inject malicious code into open-source projects. The vulnerability has a severity rating of 7.3, could give hackers elevated access to an organization’s networks, and could impact over seventy thousand open-source projects. Microsoft has released a patch, but the issue still affects code hosted on the on-premises version of Azure Pipelines. This highlights the importance of supply chain security and securing open-source code.

Why do we care?

Those Midnight Blizzard people get around.    There is a lot of tactical here — focus on training and awareness programs for employees and contractors. Emphasize robust email security solutions. Assess the security and privacy practices of their partners and vendors. Providing comprehensive ransomware defense solutions, promoting best data backup and disaster recovery practices, and offering educational resources and training to their clients and the broader community.  Prioritize the security of development and deployment pipelines, including regular vulnerability assessments and promptly applying patches.

Two trends to note – ransoms are not being paid, and operators have adjusted their tactics.  Kudos on using couriers.   

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories