Cybersecurity in numbers
How big is the threat?
70% of PL companies
experienced a cyber attack or its attempt in 2023
3/4 of successful attacks
are possible due to user error
2 mln PLN
is the average cost of handling the effects of a successful cyber attack
60% of all attempts
of cyber attacks are phishing attacks
every 11 seconds
another company's infrastructure is infected
300 days
is the average time needed to identify a new type of threat
Cybercriminals are not idle
The dynamics of attacks is accelerating
In 2023 alone, nearly 7 million new phishing websites were created, prepared by criminals to extort data from users. At the same time, specialists extracted 23 million of new, unique malware samples.
The most popular way of injecting malware are phishing attacks, i.e. attacks involving impersonating a person or entity that the user trusts in order to extort information. Such an attack is most often carried out via e-mail, SMS or other text message, or during a telephone conversation.
To better prepare for an attack, criminals often obtain a range of information available publicly on social and business portals, or company websites, in order to get to know the victim as best as possible and thus increase the chances of the attack being successful.
- Stat: 40%
- Stat: 40%
- Stat: 40%
- Stat: 40%
- Stat: 40%
- Stat: 40%
User as the most common attack vector
Data published by Cisco Umbrella indicate that among 86% of private companies and organizations surveyed, at least one user tried to connect to a phishing website prepared by cybercriminals. The fake website was usually visited after clicking on a hyperlink in an SMS or e-mail that was sent to the user.
How to effectively protect yourself against similar attacks?
- Increase employee awareness
- Implement safety procedures
- Add technical security
- Conduct regular audits
What can you do now?
The degree of exposure to specific types of attacks depends on the specificity of the industry in which a given organization operates. However, taking into account the statistics, the most effective way to protect yourself against threats and to minimize the effects of a potential attack is to increase the relatively low awareness of users regarding cyber threats.
- Employees of every private company and organization should be aware of how cyber attacks are carried out and what is the scale of threats;
- Each employee should be able to recognize and know how to deal with the most common types of cyber attacks.
It is also worth noting that nearly 90% of all attacks are motivated financially, i.e. criminals attempt to rob the user or the organization this person works for indirectly (e.g. by encrypting the hard drive and demanding a ransom) or directly (e.g. by extorting credit card details).
Infecting just one computer or user in a company network can very quickly lead to infecting the entire company infrastructure, because the malware is able to “spread” to other computers and devices. One small mistake can snowball into huge financial losses.
Detecting and neutralizing an attack in its early phase is crucial and allows to minimize the risk of unpleasant consequences.
What's worth remembering?
- Cybersecurity cannot be limited only to technological measures and IT departments;
- Equally important are investments in expanding the awareness and knowledge of all employees, in particular cyber-training;
- Private users are also often victims of phishing attacks.