This page was machine-translated and may differ from the original. View original
Manufacturing accounts for 62.5% of the economy... Caution advised for small businesses with low security levels
Emphasis on ASM and Zero Trust for Ransomware, Software Infections, and Phishing Response
Emphasis on ASM and Zero Trust for Ransomware, Software Infections, and Phishing Response
Cyber security attacks increased by approximately 40% compared to the first half of last year, indicating an urgent need for active security reinforcement.
On the 1st, the Ministry of Science and ICT, together with the Korea Internet & Security Agency, announced major cyber threat trends for the first half of 2023. According to hacking report statistics over the past three years, the number of incidents nearly doubled from 640 in 2021 to 1,142 in 2022. The number of reported security breaches in the first half of 2023 was 664, an increase of approximately 40% compared to the same period last year.
In particular, the Ministry of Science and ICT noted that the proportion of manufacturing companies among reported cases increased to 62.5%, warning that hackers are focusing their attacks on small businesses with low security levels.
The Ministry of Science and ICT stated, “Recently, attacks have become more sophisticated as hackers actively seek out targets and closely analyze the systems and mobile devices of individuals and companies to exploit vulnerabilities,” adding that special caution is required.
Among the types of domestic cyber security threats, malicious programs (ransomware) that locate backup servers and demand money (backup file infection rate of over 40%) occurred as the top priority. They demand money by infecting a network that is connected to the internet and easily exposed and accessible to the outside with ransomware.
To this end, companies must focus on Attack Surface Management (ASM) to block abnormal access to externally exposed servers and eliminate security vulnerabilities. Additionally, network segmentation and separate deployment of backup servers are essential.
For example, on the 18th, IBM provided an enterprise ASM experience through the Laundry platform. The purpose is to continuously monitor an organization's cybersecurity vulnerabilities and potential attacks, and to train organizations to implement effective attack surface management strategies by presenting an attacker's perspective.
Next, there is a method that exploits vulnerabilities in internal security software to infect employee PCs and take control of the internal network by remotely controlling malware. This poses a significant threat because malware emails are difficult to detect, and the infection status is often unknown.
Domestic and international security firms are wary of the growing threat of 'supply chain' attacks. There is a need for measures to periodically pre-inspect business software and network equipment for vulnerabilities. The ISA found that security programs accounted for approximately 54% of the 92 vulnerability reports received through its vulnerability reporting reward system.
Finally, this method exploits vulnerabilities where system developers or maintenance personnel within a company share administrator accounts on websites or cloud services, or allow access to key internal systems through a Virtual Private Network (VPN). It has been reported that the number of brokers selling corporate system administrator accounts on the dark web has increased by approximately 380.
The Ministry of Science and ICT stated that information security entities, including the public and businesses, need to make active efforts to strengthen security by raising cybersecurity awareness and expanding investment in information security. In particular, it said, “We should consider adopting a Zero Trust security model based on the premise of ‘trusting nothing.’”
The Ministry of Science and ICT stated, “We announced the ‘Zero Trust Guidelines 1.0’ on July 10 and plan to continue evolving and developing them through demonstration models,” adding, “We will also prepare and provide ‘Software (SW) Supply Chain Security Guidelines’ within the year to support the establishment of a new security system.”
Meanwhile, preparations are underway to announce measures to enhance the information security capabilities of small and medium-sized enterprises and individuals, as well as measures to foster the information security industry, in August.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














