Global survey finds 71% of cloud users suffered a malicious account takeover in 2020

Global survey finds 71% of cloud users suffered a malicious account takeover in 2020

Vectra AI, a provider of network detection and response (NDR) solutions, has released its global survey of 1,112 security professionals working in mid to large sized organisations using Microsoft Office 365.

The findings confirm that the COVID-19 pandemic has accelerated cloud migration and Digital Transformation among 88% of companies and that 71% of Microsoft Office 365 deployments have suffered an account takeover of a legitimate user’s account, not once, but on average seven times in the last year.

The fact that three in four companies have experienced malicious account takeover attacks highlights the need to track and secure identities as they move from on prem to the cloud. Just one in three security professionals believe they could identify and stop an account takeover attack immediately, the majority expect to take days or even weeks to intercept such a breach.

These challenges faced by defenders mirror the findings of the last Spotlight Report, which tracked the behaviour of four million Microsoft Office 365 customers over 90 days and discovered that 96% of networks exhibited suspicious lateral movement behaviour and that account takeovers were at the top of the list of methods used by attackers to move laterally between the cloud and network.

Ammar Enaya, Regional Director – Middle East, Turkey and North Africa (METNA), Vectra said: “We’re regularly seeing identity-based attacks being used to circumnavigate traditional perimeter defences like multi-factor authentication (MFA). Account takeovers are replacing phishing as the most common attack vector and MFA defences are speed bumps not forcefields. Organisations need to take this seriously and plan to detect and contain account compromise before a material disruption of their business occurs – malicious access, even for a short period of time, can do a tremendous amount of damage.”

However, the survey found a high level of confidence among security teams in the effectiveness of their own company’s security measures: nearly four in five claim to have good or very good visibility into attacks that bypass perimeter defences like firewalls. Yet there is an interesting contrast of opinions between management level respondents and practitioners such as Security Operations Centre (SOC) analysts, with managers exhibiting much greater confidence in their defensive abilities. Overall, the top security concerns cited by Microsoft Office365 customers are the risk of compromise of data held in the cloud, the risk of account take-over and the ability of hackers to use living-of-the-land attacks to hide their tracks.  

Tim Wade, Technical Director, CTO team, Vectra, added: “The tendency for managers to be significantly more confident that those working at the coalface suggests that there is a level of self-delusion going on here. Perhaps it’s because the metrics that are being shared with senior management often focus more on the volume of attacks stopped rather than the severity of the attack or the number of investigations that reach a firm conclusion. Whatever the reason it’s important not to be complacent and remain constantly vigilant of new types of attacks.”

The findings also reveal that a majority (58%) of security professionals say the gap between attackers and defenders is widening. The shift to cloud and adoption of remote working has heightened the threat of cyberattacks, with four in five security professionals saying that cybersecurity risks have increased in the last 12 months.

Browse our latest issue

Intelligent CIO Middle East

View Magazine Archive