I have the cure – or at least the start of it. And you do, too.
Imagine everyone on the planet improving. It wouldn’t have to be in leaps and bounds; instead, it would merely be gaining a level. Increasing skill.
Everyone needs to do that in cybersecurity. Well, almost everyone. (Let’s not tell the cybercriminals we’re doing this experiment).
You may recall my article about Cybersecurity Advocacy from a couple of weeks ago. This is the accompanying “why” article.
Cybercrime is Astoundingly Profitable
If cybercrime were a country’s GDP, it’d be third, behind the US and China. Third! Cybercrime Magazine estimated in 2020 that the global cost of cybercrime (cumulative) in 2025 would be 10.5 Trillion USD.
Bloomberg’s April 2024 article has the figure of the cybercrime GDP at $9.5 trillion, more than Germany and Japan combined. That 10.5 trillion estimate seems within the range of possibility within the course of the next year.
Headlines introduce us to breaches and 8K filing woes (at least in the US) of large companies. Consider also that small organisations are breached and sometimes ransomed regularly. They don’t tend to make the news, though. Bigger fish facing more newsworthy perils.
Does this cybercrime profit trend and these facts make you angry? Indignant?
I’d Like $75 Million USD, Please
Last week, several sources reported that an unknown large company was the largest payor of a ransom at $75 Million USD. This is nearly 3 times the largest previous ransom. The cybercrime group, Dark Angels, is fairly new – not a lot of TTPs (tactics, techniques, and procedures) to search online for Dark Angels, though they were purported to hit Johnson Controls in 2023. They’re a parallel to Oceans 11 of cybercrime – well planned, deeply detailed, and very targeted attacks.
Make no mistake, cybercrime is serious business. Serious business.
Charlatans with AI Are Aiming to Fool You
Deep fakes and hot takes make the news. Some version of a talking head that isn’t the talking head is…talking and sounds like that person.
Know this. Learn it from a Ferrari executive and his recent and clever in-the-moment thinking when a CEO impersonator tried to coax him into action. He foiled the scheme by asking it to recall a conversation. The criminals are trying to part you and your company from your money. And they’ll use newer technology to fool you if they can.
It’s so easy. Guns n’ Roses sang that in the 80s…but we won’t go there. Linda Ronstadt before then. Maybe the next song with that name will be about cybercrime, even if I have to write it. (I’m not above that).
It doesn’t matter your industry – what matters is that stuff you control. Your level and commitment to cybersecurity. If you’ve got that, they might move on to someone easier. And then we just keep working to make it universally more difficult to attack us. Hopefully. More on that.
Where’s That Leave Us? A Goal of Devaluing Cybercrime
Cybercrime is easy for talented cyberattackers. They’re also unlikely to have to face consequences if they’re not located in countries who prosecute cybercrime (or are sponsored by those countries), even if they are caught. What hope is there, since these new technologies – at least at first – seem to favor the early-adopting criminals?
Erik Boemanns of Mirability reminds us that “as defenders, we will always be trailing behind those who profit from cybercrime. So, how can we go after their profitability by reducing the value of our information and increasing their cost to ‘acquire’ it?”
What if we did seek to devalue cybercrime for these criminals? I believe that’s where we begin collective improvement – better cyber hygiene.
Cyber insurers require MFA (multifactor authentication – in addition to username and password), and in time, they’ll probably collectively also require proof of other cybersecurity practices. I attended a presentation by Travelers Insurance last week, and we talked through some of this. MFA is just one pillar, though a good one, of cybersecurity. I call it a superpower, but a single superpower doth not a cyber avengers defense-in-depth team make.
We have the frameworks and the technology to support tracking our maturity within them. We’d best put that to use. A Fortune article dropped in mid-July stating “Half of large U.S banks are failing on operational risk.” Cybersecurity (or lack of it) – one of the risks.
More to Come
This article opens the topic. There’s a lot more to come in the future, including my view of the levels of cybersecurity and why they’re important. Levels of expertise, both in general and also related to how people can serve in cybersecurity. Levels and stopping points. Evaluation and exercises.
What can you improve? What do you need help with knowing, recognizing, or executing? Is cost the biggest factor that stops that gain of additional maturity? Organisational resistance or reluctance?
Do you see the proverbial bear and have your running shoes at the ready…or on?



