Cybersecurity in numbers

How big is the threat?

70% of PL companies

experienced a cyber attack or its attempt in 2023

3/4 of successful attacks

are possible due to user error

2 mln PLN

is the average cost of handling the effects of a successful cyber attack

60% of all attempts

of cyber attacks are phishing attacks

every 11 seconds

another company's infrastructure is infected

300 days

is the average time needed to identify a new type of threat

Cybercriminals are not idle

The dynamics of attacks is accelerating

In 2023 alone, nearly 7 million new phishing websites were created, prepared by criminals to extort data from users. At the same time, specialists extracted 23 million of new, unique malware samples.

The most popular way of injecting malware are phishing attacks, i.e. attacks involving impersonating a person or entity that the user trusts in order to extort information. Such an attack is most often carried out via e-mail, SMS or other text message, or during a telephone conversation.

To better prepare for an attack, criminals often obtain a range of information available publicly on social and business portals, or company websites, in order to get to know the victim as best as possible and thus increase the chances of the attack being successful.

User as the most common attack vector

Data published by Cisco Umbrella indicate that among 86% of private companies and organizations surveyed, at least one user tried to connect to a phishing website prepared by cybercriminals. The fake website was usually visited after clicking on a hyperlink in an SMS or e-mail that was sent to the user.

How to effectively protect yourself against similar attacks?

What can you do now?

The degree of exposure to specific types of attacks depends on the specificity of the industry in which a given organization operates. However, taking into account the statistics, the most effective way to protect yourself against threats and to minimize the effects of a potential attack is to increase the relatively low awareness of users regarding cyber threats.

It is also worth noting that nearly 90% of all attacks are motivated financially, i.e. criminals attempt to rob the user or the organization this person works for indirectly (e.g. by encrypting the hard drive and demanding a ransom) or directly (e.g. by extorting credit card details).

Infecting just one computer or user in a company network can very quickly lead to infecting the entire company infrastructure, because the malware is able to “spread” to other computers and devices. One small mistake can snowball into huge financial losses.

Detecting and neutralizing an attack in its early phase is crucial and allows to minimize the risk of unpleasant consequences.

What's worth remembering?