Much is expected of our nation’s public sector. Federal, state, and local government agencies and organizations such as public hospitals and universities must maintain the critical work and essential services citizens count on while safeguarding themselves against growing global hacking collectives and malicious cybercriminals. Large-scale attacks launched by Russian cybercriminals hit several US federal government agencies, including the Department of Energy, in May and June 2023. While federal civilian agencies avoided significant impacts, the broad hacking spree may have also affected several hundred other businesses, organizations, and foreign ministries. Service providers already in the procurement process or just starting to think about securing government contracts will be well-served by understanding the cybersecurity landscape the public sector faces today. The following information highlights the most significant threats, emerging trends, and high costs of cybersecurity and cybercrime in the public sector.
Public trust is crucial for the effective functioning of the government. Citizens expect their personal information to be handled with care and for the government to ensure its security. Breaches or mishandling of data erode public trust, which can have far-reaching consequences, including diminished confidence in government institutions, decreased participation in public programs, and skepticism towards government initiatives. Data security measures demonstrate a commitment to protecting citizens’ information.
The World Economic Forum’s 2022 Global Cybersecurity Outlook reports ransomware remains the No. 1 type of cyberattack that organizations are most concerned about. The first-ever documented ransomware virus was released on unsuspecting personal computer early adopters in 1989 when 20,000 floppy disks infected with the “AIDS Trojan” or “PC Cyborg Virus” were sent to attendees of the World Health Organization’s AIDS conference. Upon booting up their computers for the 90th time after inserting the disk and executing its included questionnaire, users were told that a virus had infected their files. To regain access to their encrypted or locked files, the world’s first victims of digital extortion were instructed to send $189 to a PC Cyborg Corporation PO box in Panama.
Nearly 40 years later, everything about computers, networks, and secure technologies has changed—but ransomware is still the fastest-growing type of cybercrime. Cybersecurity Ventures estimated a ransomware attack every 11 seconds in 2021, with that frequency falling to every two seconds by 2031.
Most malicious ransomware attacks begin with an unsuspecting user clicking a corrupted link that downloads an infected file from an external source. Once opened and executed, the ransomware takes advantage of any vulnerabilities in the user’s computer and others networked across the organization.
The ransomware encrypts the computers’ files, then communicates instructions to the victims regarding regaining access to the decrypted files in exchange for a cryptocurrency ransom payment.
Among its resources for ransomware protection and response, the National Institute of Standards and Technology offers agencies and organizations eight quick steps for protecting against the threat of ransomware:
While ransomware poses a significant threat to the public sector, service providers should be aware of and learn more about other major cybersecurity threats as well.
Learn More About the Major Cybersecurity Threats Facing Today’s Public Sector
According to the FBI’s 2022 Internet Crime Report, its Internet Crime Complaint Center (IC3) received 800,944 complaints in 2022. That’s a five percent decrease from the year before, representing the only annual dip in reported cases over the past five years. The number of complaints received by the IC3 rose from 467,361 in 2019 to 791,790 in 2020 before peaking at 847,376 in 2021. Regardless of the number of complaints, the potential total financial losses from reported cybercrimes climbed from $6.9 billion in 2021 to a record $10.2 billion in 2022.
Moreover, the officially reported numbers are likely significantly lower than the true volume of cybercrime taking place. In reports from the US Attorney General’s Cyber-Digital Task Force, the Department of Justice says as much as 85 percent of all cybercrime may go unreported. Cyberattacks can be well-hidden and well-organized. Well-funded malicious actors can spend more on attack innovations than organizations spend on protection.
Public hospitals and healthcare providers house patient data and personal information on networks supporting potentially outdated or vulnerable devices and can be a lucrative target for greedy cybercriminals. Moody’s Investors Service declared hospitals, as well as public utilities, including electric, water, and gas, to be among the sectors facing the highest risk of cyberattacks.
Infrastructure facilities are also becoming popular targets as cyberattacks evolve as a weapon of war—one with the potential to inflict devastating blows to essential services. Russia’s invasion of Ukraine includes near-constant cyberattack efforts against the Ukrainian government and civilian infrastructure. According to a report from Google’s Mandiant research unit, more destructive cyberattacks were observed on Ukrainian targets in just the first four months of 2022 than in the previous eight years combined
Several emerging trends in cybersecurity are shaping the landscape and requiring increased attention in the public sector, and it’s crucial for Service Providers to understand and keep up with these trends to secure and maintain government contracts.
Learn More About Emerging Trends in the Cybersecurity Space
Cybercriminals, once thought to focus mainly on large enterprises, often attack the easiest targets, regardless of their size. Large and small organizations should commit to increased cybersecurity to protect themselves and the people they serve. Some items to budget include:
Cybersecurity costs can vary significantly based on the size and nature of the organization, industry sector, geographic location, regulatory environment, and specific cybersecurity needs and risks. Furthermore, the impact of cybercrime also includes the financial costs of incidents, reputational costs, and public health and safety impact.
Learn More About the Costs of Cybersecurity and Impact of Cybercrime