Book chapter · 2023
Why Cyberattacks Disrupt Society and How to Mitigate Risk
In Cybersecurity for Decision Makers, pp. 1–28, CRC Press / Taylor & Francis · Published
Summary
What question does this chapter answer?
Why should decision makers be aware of cybersecurity in the context of Industry 4.0, and how can organizations using Industry 4.0 assess their cybersecurity vulnerabilities and mitigate cyberattack risk?
What did the chapter find?
Reviewing 25 major global cyberattacks from 2020–2022, the authors classify 44% as extortion, 32% as service disruption and 24% as data theft; 36% involved bitcoin ransom, with 20% targeting customers or end users and 16% targeting companies. They trace many incidents to missed warnings, unpatched or unmonitored systems, insecure contractors and software updates, and recommend regular log audits, prompt patching, scanning of software updates, awareness training, contractual cybersecurity clauses, intrusion detection systems and international cooperation, including regulating bitcoin.
Why does it matter?
Cyberattacks have crippled governments and companies, disrupting supply chains, fuel and food supply, healthcare and public services, and the FBI reported losses exceeding $4.2 billion from internet crime in 2020. The chapter gives decision makers concrete lessons from real incidents and argues that organizations adopting Industry 4.0 technologies must assess their vulnerabilities and put benchmark-based cybersecurity policies in place, or users will lose trust.
Key findings
- The chapter classifies 25 major global cyberattacks from 2020–2022 by type, finding that extortion was the most common central motive at 44%, followed by service disruption at 32% and data theft at 24%.
- Of the major cyberattacks reviewed, 36% were for bitcoin ransom — 20% directed at customers or end users and 16% at companies — while only 8% extorted governments, many of which refused to pay.
- Service disruption cyberattacks (32% of incidents reviewed) were largely attributed to the Russian invasion of Ukraine, which the authors estimate accounted for 20% of the major cyberattacks.
- Among the major cyberattacks reviewed, data thefts targeted pharmaceutical drug trade secrets (8%) and government defense industry classified material (12%), which the authors consider potentially the costliest in strategic terms despite data theft being the least common attack type.
- In the 2021 Colonial Pipeline ransomware attack, the company paid $4.4 million in bitcoin to the DarkSide group; the U.S. Department of Justice later recovered 63.7 bitcoins (about $2.3 million).
- The FBI received 791,790 complaints of suspected internet crime in 2020 with reported losses exceeding $4.2 billion; phishing, non-payment/non-delivery scams and ransomware were the top three crimes.
- The authors recommend checking system integrity and audit logs regularly, isolating and cleaning systems when unusual activity is detected, installing security patches on schedule, and adding cybersecurity risk management awareness training for decision makers and end users.
Source: Strang & Vajjhala (2023), In Cybersecurity for Decision Makers, pp. 1–28, CRC Press / Taylor & Francis. DOI: 10.1201/9781003319887-1
Chapter at a glance
| Research question | Why should decision makers be aware of cybersecurity in the context of Industry 4.0, and how can organizations assess their cybersecurity vulnerabilities? |
|---|---|
| Design | Narrative review and case analysis of major publicly reported cyberattacks during 2020–2022, classified by attack type, hacker source and central motive. |
| Data | 25 major global cyberattacks (Table 1.1), including BlueLeaks, SolarWinds, Colonial Pipeline, JBS, Kaseya, Ireland’s HSE, Vastaamo, the Russian cyberattacks on Ukraine and Costa Rica. |
| Methods | Descriptive classification of incidents into data theft, service disruption and extortion, cross-tabulated by central motive (Table 1.2), plus review of Industry 4.0 security issues. |
| Main result | Extortion was the most common type (44%), followed by service disruption (32%) and data theft (24%); nearly all extortion demanded payment in bitcoin. |
| Implication | Decision makers should audit logs, patch promptly, scan software updates, train staff, add cybersecurity clauses to procurement contracts and deploy intrusion detection systems for Industry 4.0 environments. |
| Citation | Strang & Vajjhala (2023) · DOI 10.1201/9781003319887-1 |
Opening summary
Cybersecurity attacks have crippled governments as well as private and public companies around the world (Sawik 2022). The impacts have been serious and costly, including disrupting the supply chain, impeding e-commerce transactions, theft of government classified information and publicly disseminating confidential personal data. The US Federal Bureau of Investigations (FBI, 2021) estimated the total cost of cyber terrorism was $4.2 billion USD by the end of 2021 (data for 2022 were not yet analyzed at the time of writing). The BlueLeaks cyberattack on 271 US anti-terrorism agencies resulted in 270 gigabytes holding 700,000 law enforcement police officers’ classified personal data being broadcast on Twitter and stored on a public website for free download (Lee 2020). Prior to the COVID-19 pandemic, there were 1244 data breaches in the US, with over 446.5 million information records stolen, which cost stakeholders over $575 billion (Sawik 2022).
This chapter has no published abstract; its opening paragraph is reproduced from Cybersecurity for Decision Makers.
Key terms
- Industry 4.0
- The fourth industrial revolution: the digitalization of industry through technologies such as the Internet of Things, cyber-physical systems, big data analytics, cloud computing, artificial intelligence and autonomous machines.
- Cyber extortion (ransomware)
- A cyberattack that demands money or assets, often by encrypting critical systems with ransomware or threatening to publish stolen data until a ransom, typically in bitcoin, is paid.
- Parkerian hexad
- Six elements of information security — confidentiality, control, integrity, authenticity, availability and utility — that cybersecurity investment aims to protect.
Limitations
- Many cyberattacks for data theft, service disruption and extortion likely took place that were not reported publicly and therefore could not be included in the chapter.
- The chapter does not review every cyberattack; it covers major global cyberattacks representative of type, motive and impact, up to the time of writing in 2022.
- The authors call for detailed analysis in developing countries, comparison with developed countries, and future research focusing on each cybersecurity challenge separately.
How to cite
Strang, K. D., & Vajjhala, N. R. (2023). Why Cyberattacks Disrupt Society and How to Mitigate Risk. In Narasimha Rao Vajjhala, Kenneth David Strang (Eds.), Cybersecurity for Decision Makers (pp. 1–28). CRC Press / Taylor & Francis. https://doi.org/10.1201/9781003319887-1
BibTeX
@incollection{strang2023cyberattacks,
title = {Why Cyberattacks Disrupt Society and How to Mitigate Risk},
author = {Strang, Kenneth David and Vajjhala, Narasimha Rao},
booktitle = {Cybersecurity for Decision Makers},
editor = {Narasimha Rao Vajjhala and Kenneth David Strang},
pages = {1--28},
year = {2023},
publisher = {CRC Press / Taylor & Francis},
doi = {10.1201/9781003319887-1},
url = {https://doi.org/10.1201/9781003319887-1}
}Related research