City
Epaper

Cybercriminals wiped out logs in 82% of attacks with missing telemetry: Report

By IANS | Updated: November 16, 2023 15:50 IST

New Delhi, Nov 16 Cybercriminals disabled or wiped out logs in 82 per cent of attacks with missing ...

Open in App

New Delhi, Nov 16 Cybercriminals disabled or wiped out logs in 82 per cent of attacks with missing telemetry between January 1, 2022, to June 30, 2023, a new report said on Thursday.

Telemetry automatically gathers, transmits and measures data from remote sources, using sensors and other devices to collect data.

As explained by the cybersecurity firm Sophos, gaps in telemetry decrease much-needed visibility into an organisation’s networks and systems, especially since attacker dwell time (the time from initial access to detection) continues to decline, shortening the time defenders have to effectively respond to an incident.

In the report, the researchers classified ransomware attacks with a dwell time of less than or equal to five days as “fast attacks,” which accounted for 38 per cent of the cases studied.

“Slow” ransomware attacks are those with a dwell time greater than five days, which accounted for 62 per cent of the cases.

"Missing telemetry only adds time to remediations that most organisations can’t afford. This is why complete and accurate logging is essential, but we’re seeing that, all too frequently, organisations don’t have the data they need," said John Shier, field CTO, Sophos.

According to the researchers, when examining these “fast” and “slow” ransomware attacks at a granular level, there was not much variation in the tools, techniques, and living-off-the-land binaries (LOLBins) that attackers deployed, suggesting defenders don’t need to reinvent their defensive strategies as dwell time shrinks.

"Cybercriminals only innovate when they must, and only to the extent that it gets them to their target. Attackers aren’t going to change what’s working, even if they’re moving faster from access to detection," said Shier.

The report is based on 232 Sophos Incident Response (IR) cases across 25 sectors. Targeted organisations were located in 34 different countries across six continents.

About 83 per cent of cases came from organisations with fewer than 1,000 employees.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

Other Sports5th T20I: Happy that Yuvraj still holds fastest T20I fifty record, says Pandya after 16-ball fifty

NationalOdisha vigilance arrests Additional Tehsildar in Jajpur

InternationalUS says it is grateful as Pakistan weighs Gaza troop role

Other Sports5th T20I: ‘Surya the batter’ went missing somewhere, he will be back stronger, says Yadav

NationalDrug factory busted in Rajasthan; 40 kg mephedrone among seizures

National Realted Stories

NationalDrug supply chain largely curbed in Mizoram, full eradication still a challenge: CM Lalduhoma

NationalMaram Naga delegation meets Manipur Governor; seeks protection of ethnic, cultural heritage

NationalNational Herald case: ED challenges trial court relief to Sonia, Rahul

NationalChandrababu Naidu meets HM Amit Shah, discusses Andhra projects

NationalKarnataka Hate Speech Regulation Bill: Union Minister Shobha Karandlaje urges Governor to withhold assent