{"id":41075,"date":"2021-05-26T16:00:31","date_gmt":"2021-05-26T16:00:31","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=93582"},"modified":"2021-05-26T16:00:31","modified_gmt":"2021-05-26T16:00:31","slug":"becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/","title":{"rendered":"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats"},"content":{"rendered":"<p>In part three of this blog series on aligning security with business objectives and risk, we explored what it takes for security leaders to shift from looking at their mission as purely defending against technical attacks, to one that focuses on protecting valuable business assets, data, and applications.<\/p>\n<p>As businesses begin reimagining their future in a post-pandemic world, most are pivoting to a digital-first approach to take full advantage of technological innovation (much of which was adopted in haste). The pandemic has accelerated three existing trends and the tension between them: how to remain relevant against a backdrop of consumer and market demands, how to react and respond to evolving cyber threats, and how to do this reliably while reducing complexity and cost.<\/p>\n<p>Becoming a resilient organization requires collaboration between business and security leaders and a lifecycle approach to continuous improvement.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93583 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/Incident.png\" alt=\"Visual chart depicting the four stages of the life cycle of an incident: Before, during, and after an incident and the lessons learned. \" width=\"1978\" height=\"684\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/Incident.png 1978w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/Incident-300x104.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/Incident-1024x354.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/Incident-768x266.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/Incident-1536x531.png 1536w\" sizes=\"auto, (max-width: 1978px) 100vw, 1978px\"><\/p>\n<p><em>Figure 1. The cyclical stages of an incident.<\/em><\/p>\n<p>In this blog, we delve deeper into specific themes in recent cyberattack trends\u2014how and why they work so effectively\u2014and strategies to mitigate them.<\/p>\n<h2>On-premises vs. cloud security<\/h2>\n<p>As we\u2019ve seen from the progression of headline-grabbing attacks over the course of this blog series, today\u2019s attackers have choices. They can remain on-premises and have a better chance of lingering unseen in the complexity of multiple generations of legacy technology, or they can elevate privileges and move to the cloud, where there\u2019s a higher risk of detection. In the most recent nation-state attack, <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/#:~:text=HAFNIUM%20has%20previously%20compromised%20victims,file%20sharing%20sites%20like%20MEGA.\" target=\"_blank\" rel=\"noopener noreferrer\">HAFNIUM took the path of least resistance<\/a> and targeted organizations through on-premises <a href=\"https:\/\/docs.microsoft.com\/en-us\/exchange\/exchange-server?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Exchange Servers<\/a>, leveraging a zero-day exploit to gain backdoor access to data centers. After Microsoft released critical out-of-band updates, attackers were quick to seek out and compromise unpatched servers in a race to take advantage of the situation before those doors were closed.<\/p>\n<p>The Exchange attack illustrates challenges faced by companies in managing a complex hybrid of on-premises and cloud that spans many generations of technology. For many organizations, it can be a costly operation to upgrade systems; so, security teams are often asked to protect both old and new technology at the same time. Organizations need to simplify the management of this complex mix because attackers are always looking for vulnerabilities. The good news is that cloud security is no longer just for cloud resources; it\u2019s extending to cover on-premises resources, up to and including the 50 to 100-year-old operational technology (OT) equipment that\u2019s controlled by computer technology retrofitted 30 to 50 years ago.<\/p>\n<p>Your security team can reduce risk by prioritizing the cloud as the preferred source of security technology. This will simplify adoption, reduce maintenance overhead, ensure the latest innovations and capabilities, and provide unified visibility and control across multiple generations of technology. No longer are we just referring to cloud security, but rather security delivered from the cloud.<\/p>\n<h2>Ransomware<\/h2>\n<p>Criminal organizations are increasingly relying on cybercrime as a high-reward, low-risk (illicit) line of business. However, it\u2019s the evolution of <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/03\/05\/human-operated-ransomware-attacks-a-preventable-disaster\/\" target=\"_blank\" rel=\"noopener noreferrer\">human-operated ransomware<\/a> that\u2019s now driving the business need to address longstanding security hygiene and maintenance issues. Ransomware\u2019s evolution can be <a href=\"https:\/\/en.wikipedia.org\/wiki\/WannaCry_ransomware_attack\" target=\"_blank\" rel=\"noopener noreferrer\">traced to WannaCry<\/a> and <a href=\"https:\/\/attack.mitre.org\/software\/S0368\/\" target=\"_blank\" rel=\"noopener noreferrer\">NotPetya malware<\/a>, which fused large-scale compromise techniques with an encryption payload that demanded ransom payments in exchange for a decryption key. Sometime around June 2019, the new generation of human-operated ransomware started infecting systems, expanding into an enterprise-scale operation that blends targeted attacks and extortion.<\/p>\n<p>What makes human-operated ransomware so dangerous? Unlike most cyber threats, these are not preprogrammed attacks. Human attackers know the weaknesses in your networks and how to exploit them. Attacks are multistage and opportunistic\u2014they might gain access via remote desktop protocol (RDP) brute force or through banking trojans, then decide which networks are most profitable. Like nation-state attacks, these breaches can have dwell times lasting from minutes to months. Human operators may also deliver other malicious payloads, steal credentials, or exfiltrate data. Some known human-operated ransomware campaigns that Microsoft actively monitors include REvil, Samas, Bitpaymer, and Ryuk.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93584 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/attack-paths.png\" alt=\"Attack paths of human-operated ransomware.\" width=\"1676\" height=\"746\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/attack-paths.png 1676w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/attack-paths-300x134.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/attack-paths-1024x456.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/attack-paths-768x342.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/05\/attack-paths-1536x684.png 1536w\" sizes=\"auto, (max-width: 1676px) 100vw, 1676px\"><\/p>\n<p><em>Figure 2: Human-operated ransomware\u2014attack paths.<\/em><\/p>\n<p>Human-operated ransomware is an extortion model that can use any one of multiple attack vectors. These attacks are often highly damaging and disruptive to an organization because of the combination of:<\/p>\n<ol>\n<li><strong>Broad access to business-critical assets:<\/strong> Attackers rapidly gain broad enterprise access and control through credential theft.<\/li>\n<li><strong>Disrupt business operations:<\/strong> The extortion business model requires inflicting the maximum pain on the organization (while still allowing recovery) in order to make paying the ransom attractive.<\/li>\n<\/ol>\n<p>By denying access to business-critical data and systems across the enterprise, the attackers are more likely to profit, and organizations are more likely to suffer significant or material impact.<\/p>\n<p>In the same way COVID-19 has shifted industry perceptions regarding bring-your-own-device (BYOD) policies and remote work, human-operated ransomware is poised to trigger seismic shifts in cybersecurity. Organizations who fail to prepare for these evolving threats face the prospect of performing mass restores of systems and data or paying the ransom (not recommended).<\/p>\n<p>This is particularly true if they have any of these commonly held (and dangerous) false beliefs:<\/p>\n<ul>\n<li>Attackers aren\u2019t interested in us because we\u2019re just: a small organization, don\u2019t have secrets, not a government, or other seemingly relevant characteristics.<\/li>\n<li>We are safe because we have firewalls.<\/li>\n<li>A password is good enough for admins; so multifactor authentication (MFA) can be deferred.<\/li>\n<li>Attackers won\u2019t find unpatched VPNs and operating systems; so, maintenance can be deferred.<\/li>\n<li>We don\u2019t apply security updates to internal systems like domain controllers to avoid impacting availability and performance.<\/li>\n<li>Security operations (SecOps) can manually write every alert and respond using a SIEM and a firewall; so, modernization with high-quality XDR detections and SOAR can be deferred.<\/li>\n<\/ul>\n<p>If your organization is targeted, we strongly discourage paying any ransom, since this will incentivize future attacks. Also, there\u2019s no guarantee that payment will get you the promised decryption key, or even that the attackers won\u2019t sell your data on the dark web anyway. <strong>For a specific plan of how to address ransomware, see our <a href=\"https:\/\/docs.microsoft.com\/en-us\/security\/compass\/human-operated-ransomware\" target=\"_blank\" rel=\"noopener noreferrer\">downloadable Ransomware recommendations PowerPoint<\/a>.<\/strong><\/p>\n<p>On the upside, having a <a href=\"https:\/\/docs.microsoft.com\/en-us\/compliance\/assurance\/assurance-resiliency-and-continuity\" target=\"_blank\" rel=\"noopener noreferrer\">business continuity and disaster recovery<\/a> (BCDR) solution can provide a crucial safety net. <a href=\"https:\/\/www.datto.com\/resource-downloads\/Datto2019_StateOfTheChannel_RansomwareReport_NL-8.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Datto\u2019s Global Ransomware Report 2020<\/a> indicates that three-out-of-four managed service providers (MSPs) report that clients with BCDR solutions recovered from a ransomware attack within 24 hours. However, just having a BCDR plan is not enough; you need an immutable backup that cannot be corrupted or deleted as attackers try to corrupt these backups.<\/p>\n<p>This control needs to be implemented effectively across all generations of technology, including on-premises and in the cloud. <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/information-protection\" target=\"_blank\" rel=\"noopener noreferrer\">Information protection<\/a> and file encryption can also make data unreadable, even if exfiltrated.<\/p>\n<h2>Insider threats<\/h2>\n<p>Many data leaks can be attributed to accidents by insiders, but the risk posed by deliberate internal threats is on the rise as well\u2014<a href=\"https:\/\/www.cybersecurity-insiders.com\/wp-content\/uploads\/2019\/11\/2020-Insider-Threat-Report-Gurucul.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">68 percent of organizations<\/a> feel \u201cmoderately to extremely vulnerable\u201d to all kinds of insider attacks. The same percentage confirms that insider attacks are becoming more frequent. Anyone who has access to an organization\u2019s confidential data, IT, or network resources is a potential risk, whether they intend to do harm or not. This could include employees, consultants, vendors, former employees, business partners, or even a board member.<\/p>\n<p>Recent examples include a <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/amazon-employee-14m-insider\/\" target=\"_blank\" rel=\"noopener noreferrer\">former Amazon finance manager<\/a> charged in a $1.4 million insider trading scheme, a <a href=\"https:\/\/community.shopify.com\/c\/Shopify-Discussion\/Incident-Update\/m-p\/888971\/highlight\/true#M197487\" target=\"_blank\" rel=\"noopener noreferrer\">Shopify data breach<\/a> carried out by two employees, and an insider attack at <a href=\"https:\/\/www.bankinfosecurity.com\/prosecutors-insider-sabotaged-medical-equipment-shipments-a-14172\" target=\"_blank\" rel=\"noopener noreferrer\">Stradis Healthcare<\/a> carried out by the former vice president of finance that \u201cdisrupted the delivery of personal protective equipment in the middle of a global pandemic.\u201d Deliberate insider threats straddle both the physical and digital workspace, but organizations can protect themselves by looking for signs, including:<\/p>\n<p><strong>Digital warning signs<\/strong><\/p>\n<ul>\n<li>Accessing data not associated with their job function.<\/li>\n<li>Using unauthorized storage devices.<\/li>\n<li>Network crawling and searches for sensitive data.<\/li>\n<li>Data hoarding or copying sensitive files.<\/li>\n<li>Emailing sensitive data outside the organization.<\/li>\n<\/ul>\n<p><strong>Behavioral warning signs<\/strong><\/p>\n<ul>\n<li>Attempts to bypass security.<\/li>\n<li>Frequently in the office during off-hours.<\/li>\n<li>Displays disgruntled behavior.<\/li>\n<li>Violates corporate policies.<\/li>\n<li>Discusses resigning or new opportunities.<\/li>\n<\/ul>\n<p>The key to preventing insider threats is to detect a violation before it happens. This means being empathetic to your organization\u2019s changing environment and managing potential stressors that could lead to aberrant behavior. Being cognizant of employee wellbeing is not only in the best interests of your staff, it also drastically reduces the occurrence of insider threats for your organization. Microsoft invests in mitigating both accidental and deliberate insider threats with <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/compliance\/insider-risk-management\" target=\"_blank\" rel=\"noopener noreferrer\">insider risk management<\/a>, <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/compliance\/use-notifications-and-policy-tips\" target=\"_blank\" rel=\"noopener noreferrer\">policy tips<\/a>, and more.<\/p>\n<h2>Overcoming analyst fatigue<\/h2>\n<p>As the dust settles after the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/01\/20\/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop\/\" target=\"_blank\" rel=\"noopener noreferrer\">double-impact of the Nobelium<\/a> and Hafnium attacks, we\u2019re returning to a \u201cnormal baseline\u201d of steadily increasing impact, volume, and sophistication of attacks. This lack of relief hits security professionals hardest, particularly analysts in security operations responding to these incidents.<\/p>\n<p>The talented security professionals who silently bear the burden of attackers\u2019 profit models often experience a high likelihood of burnout. <a href=\"https:\/\/www.thepsyberproject.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">According to PsyberResilience<\/a>, the list of reasons for burnout among security professionals is long: fear of letting the organization down by missing that one threat amongst thousands every day; exhausting work schedules; fatigue from trying to keep up with new threats and technologies; the emotional toll of facing down criminals and witnessing their lack of morality.<\/p>\n<p>Security teams need real help, and they need to feel supported and connected to the mission. Here are a few tips that can go a long way:<\/p>\n<ul>\n<li><strong>Show your appreciation:<\/strong> The first minimum step for business leaders is to thank these hardworking people and get a basic understanding of what it\u2019s like to experience these attacks from the ground level. Just as CEOs and business leaders should take time out to meet the people who make business operations work (like factory workers, truck drivers, nurses, doctors, cooks, engineers, and scientists), they should also do the same with security operations personnel to show the importance of the work to keep the organization safe every day.<\/li>\n<li><strong>Enable automation and orchestration:<\/strong> This is critical to removing redundant, repetitive workflows or steps that burn up work hours and burn out employees. <a href=\"https:\/\/docs.microsoft.com\/azure\/sentinel\/automation-in-azure-sentinel\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Sentinel<\/a> and <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/security\/defender-endpoint\/automated-investigations\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft 365 Defender<\/a> automate investigation and remediation tasks for many incidents, reducing the burden of repetitive work on analysts. Different security solutions in your enterprise need to <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-threat-intelligence\" target=\"_blank\" rel=\"noopener noreferrer\">see and share threat intelligence<\/a>, driving a unified response across on-premises and multi-cloud environments.<\/li>\n<li><strong>Bring in help:<\/strong> Many companies find it difficult to recruit and retain security professionals, especially organizations that have a smaller security team. Supplementing your team with experts from service providers can help you bring in top talent for the limited times you need them or help scale the experts you have by shifting high-volume frontline analyst work to the service provider.<\/li>\n<li><strong>Take a collaborative approach:<\/strong> Reach out to peers in other industries to learn about their challenges. How do hospitals secure their patient data? How is cybersecurity done in retail operations, airlines, or government offices? Looking into different verticals might offer some new ideas and inspiration. An army of interconnected defenders provides more clarity and oversight than any single organization can maintain. For more technical information about how this works, learn about the <a href=\"https:\/\/medium.com\/@johnlatwc\/the-githubification-of-infosec-afbdbfaad1d1\" target=\"_blank\" rel=\"noopener noreferrer\">community-based approach to information security<\/a>.<\/li>\n<\/ul>\n<h2>Augmented intelligence and deepfakes<\/h2>\n<p>Using machine learning and automation has proven to be an incredible tool for defenders to detect and respond to threats faster. However, attackers also have access to similar technology and are leveraging this to their advantage. In another example of the cyber and physical worlds coming together, cybercriminals were able to create a near-perfect impersonation of a chief executive\u2019s voice <a href=\"https:\/\/en.wikipedia.org\/wiki\/Deepfake\" target=\"_blank\" rel=\"noopener noreferrer\">using deepfake technology<\/a>\u2014tricking the company into <a href=\"https:\/\/www.wsj.com\/articles\/fraudsters-use-ai-to-mimic-ceos-voice-in-unusual-cybercrime-case-11567157402\" target=\"_blank\" rel=\"noopener noreferrer\">transferring $243,000<\/a> to their bank account. Attackers combined machine learning and AI with social engineering to convince people to move the money.<\/p>\n<p>While still rare, <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/10\/22\/cyberattacks-against-machine-learning-systems-are-more-common-than-you-think\/\" target=\"_blank\" rel=\"noopener noreferrer\">AI and machine learning attacks like this are becoming more common<\/a>. Attackers can make deepfake using public recordings of their target from earnings calls, interviews, and speeches, mimicking their mannerisms and using the technology as a kind of mask. Despite the advanced technology required for one of these attacks, the defense may be refreshingly straightforward and non-technical\u2014if in doubt, call the person back. Using a secondary authentication for high-value transactions can also provide an additional secure step in the approval process, making it difficult for attackers to anticipate and fake out all of the channels at once.<\/p>\n<p>With the use of AI and machine learning becoming more prolific in the defender\u2019s kit bag, cybercriminals have also taken to attacking and poisoning the algorithms that are used to detect anomalies; often flooding the algorithm with data to skew results or generate false positives. In short, the human intelligence layer remains critical to providing contextual awareness and understanding of new cyber threats, helping to decipher the evolving tactics and techniques designed to evade detection.<\/p>\n<h2>Stay tuned<\/h2>\n<p>The next post in this series will focus on how your organization can pull all these concepts together into a security strategy that integrates with your business priorities, risk frameworks, and processes.<\/p>\n<p>If you want to read ahead, you can check out the <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/secure\/\" target=\"_blank\" rel=\"noopener noreferrer\">secure methodology<\/a> in the cloud adoption framework.<\/p>\n<h2>Learn more<\/h2>\n<p>Read the previous blogs in this series:<\/p>\n<p>To learn more about Microsoft Security solutions, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener noreferrer\">visit our website<\/a>. Bookmark the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener noreferrer\">Security blog<\/a> to keep up with our expert coverage on security matters. Also, follow us at <a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">@MSFTSecurity<\/a> for the latest news and updates on cybersecurity.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/05\/26\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn how your infrastructure and security operations can make you vulnerable to insider threats, ransomware, weaponized AI, and more.<br \/>\nThe post Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41076,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[7835,347],"class_list":["post-41075","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-ciso","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-26T16:00:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/05\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1978\" \/>\n\t<meta property=\"og:image:height\" content=\"684\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats\",\"datePublished\":\"2021-05-26T16:00:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/\"},\"wordCount\":2229,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png\",\"keywords\":[\"CISO\",\"Cybersecurity\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/\",\"name\":\"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png\",\"datePublished\":\"2021-05-26T16:00:31+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png\",\"width\":1978,\"height\":684},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CISO\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/ciso\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/","og_locale":"en_US","og_type":"article","og_title":"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-05-26T16:00:31+00:00","og_image":[{"width":1978,"height":684,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/05\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats","datePublished":"2021-05-26T16:00:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/"},"wordCount":2229,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/05\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png","keywords":["CISO","Cybersecurity"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/","url":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/","name":"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/05\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png","datePublished":"2021-05-26T16:00:31+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/05\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/05\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats.png","width":1978,"height":684},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/becoming-resilient-by-understanding-cybersecurity-risks-part-4-navigating-current-threats\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"CISO","item":"https:\/\/www.threatshub.org\/blog\/tag\/ciso\/"},{"@type":"ListItem","position":3,"name":"Becoming resilient by understanding cybersecurity risks: Part 4\u2014navigating current threats"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41075"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41075\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41076"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}