If we have selected the wrong experience for you, please change it above.
Current trends in cyber resilience
Marc Ruef has worked in cyber security since the late 1990s and is the founder of computec.ch, the best known German-language computer security portal. He published his first book at the age of 18 and went on to write “Hacking Intern” (published by Data Becker Verlag) and “Die Kunst des Penetration Testing” (“The Art of Penetration Testing”), which was published by C&L Verlag, among other titles. Over the last 25 years, Marc Ruef has collaborated on 16 books, published more than 275 specialist articles in seven languages and given over 200 interviews. He is one of the most widely-read German-language writers in his area. He also lectures at a number of Swiss higher education institutions, including ETH Zurich, the University of Applied Sciences in Business Administration Zurich, Lucerne University of Applied Sciences and Arts, and the Institute of Communication and Leadership in Lucerne. Marc Ruef is co-founder of scip AG, a Zurich-based company that has been providing consultancy in cyber security since 2002. He heads scip AG’s research department, which focuses on unconventional projects, such as car hacking and the testing of medical equipment.
Opens in new window
swissVR Monitor: You have proven skills and expertise in the cyber field. How do you see companies’ cyber resilience having improved over the last few years?
Marc Ruef: Cyber resilience has improved markedly. Many companies now understand cyber security as a crucial aspect of corporate risk, and members of management teams are now much more likely to be discussing digital risks and regulatory requirements. However, cyber crime has also become more professional over that time: ransomware groups now operate like industrial service providers with specific roles, workloads and business models, so the race against the criminals continues.
swissVR Monitor: Our survey findings show that more than one company in three has been the victim of a damaging cyber attack. Where do you see the major vulnerabilities? And where do companies need to put most effort into making their systems more secure?
Marc Ruef: Theft of log-in credentials is still the greatest risk: successful attacks resulting from phishing, data theft and compromised user accounts can have a devastating impact on a company. And most recently, we have seen a ramping-up of the risk from third-party providers and supply chains. The increasing complexity and multifaceted nature of modern systems involve risks that are not always evident, so companies are therefore more likely to downplay their significance.
swissVR Monitor: Three years ago, around one company in four reported being the victim of a cyber attack. How do you explain the increase, given that businesses are now much more aware of cyber-related issues?
Marc Ruef: There’s no contradiction between a greater frequency of attacks and a better understanding of cyber risk. The complexity of systems and, hence, the extent of companies’ vulnerability to cyber attack has increased, so it hasn’t become any easier to protect systems. Meanwhile, cyber crime has become a business model and is constantly being refined. We are now seeing the first, but very serious, impacts of AI on cyber security, with both companies and criminals benefitting from the new opportunities AI brings.
swissVR Monitor: What measures do you think are most effective in preparing employees for cyber attacks?
Marc Ruef: Successful implementation of cyber security does not start with procuring expensive technology but rather with the company’s culture of security, which dictates its specific needs and its scope for action in this area. Staff training is crucial to reducing vulnerability to attack, and over recent decades, companies have had access to a range of technological means to deploy and optimise on an ongoing basis. These include traditional defences, such as firewalls, network segmentation, anti-virus programs and regular systems updates.
swissVR Monitor: Our latest survey shows that more than half of all companies do not have plans in place for restoring essential core IT process following a cyber attack without incurring unacceptable costs or damage. What should plans for such a scenario actually look like? And how should they be tested?
Marc Ruef: Caution and discipline are the key requirements for a secure company. Businesses need to take the time to prepare thoroughly for a crisis, identifying core processes that are at risk and measures to contain the impact of an attack and to restore systems. It is devastating when companies do not tackle this issue early enough: once the crisis has happened, they are in survival mode and simply do not have time to think carefully about the decisions they are making, let alone make plans.