The Chartered Accountant | Technology September 2024 • Pages 101–103

Rising Threats: Navigating the Complex World of Cyber Security Attacks

CA. Anjali Ganotra
Member of the Institute
A cyber security threat involves the illicit use of software tools to breach security measures and gain unauthorized access to private data belonging to individuals, firms, organizations, or governments. With critical infrastructure such as nuclear and power sectors increasingly reliant on computer networks, digital disruptions threaten national security, public safety, and institutional reputation.

1. Global Context & Key Statistics

During the World Telecommunication Development Conference held in Kigali, Rwanda (June 2022), global delegates emphasized the necessity of developing a proactive cyber security culture and implementing robust assurance practices.

99%
Respondents expecting identity-related compromises in upcoming years (CyberArk 2023 Report)
58%
Compromises expected to occur during digital transformation initiatives
+51%
Increase in reported ransomware incidents in India (CERT-In H1-2022 Report)

2. Classification of Malware Threats

Malware (malicious software) manifests in diverse forms designed to compromise system security, spy on users, or disrupt digital workflows:

  • Spyware: Infiltrates systems via links and acts as digital espionage tools (e.g., Pegasus) capable of extracting private files and locking data.
  • Trojan Horse: Disguises itself as legitimate files; while non-replicating, it hampers performance, leaks data, and spreads when embedded files are transferred.
  • Bugs: Design or development flaws in software code that produce unexpected errors or functional failures.
  • Viruses: Programs designed to alter device functionality, corrupt storage, or leak confidential data to external actors.
  • Adware: Inundates user interfaces and applications with excessive advertisements, severely degrading system processing speeds.
  • Worms: Self-replicating malware that spreads autonomously across network connections, disrupting normal operations rapidly.
  • Bots: Automated programs that, if compromised, can execute unauthorized tasks, transmit spam, or flood web applications.
  • Ransomware: An extended threat vector where malware holds critical data hostage, demanding financial compensation for its restoration.

3. Workplace Vulnerabilities & Attack Vectors

SQL Injection (SQLi)

Occurs when malicious actors insert structured query language code into web application input fields. Successful exploits allow attackers to manipulate backend databases, access sensitive consumer or financial data, alter or delete records, and execute administrative operations. For instance, gaining administrative email access could enable fraudulent fund transfer instructions.

Man-in-the-Middle (MitM) Attacks

Takes place when sensitive transactions or file transmissions occur over unsecured public Wi-Fi networks (e.g., coffee shops). Interceptors eavesdrop on unencrypted data exchanges without the user's consent.

Phishing & Social Engineering

Phishing: Fraudulent emails (e.g., cash prize claims) containing malicious links that silently install data-exfiltrating software upon being clicked.
Social Engineering: Manipulation of human psychology to deceive victims into surrendering access or credentials. Examples include impersonating bank officials to obtain OTPs or impersonating family contacts to request financial transfers.

Insider Threats & Corporate Espionage: 
Occurs when employees, contractors, or business partners intentionally leak confidential data or compromise network operations. Competitors may also use deceptive interview setups (e.g., malicious links in video call chats) to trigger data leaks from company laptops.

4. Infrastructure Attacks & Vulnerabilities

  • Denial-of-Service (DoS): Floods a target server with illegitimate request traffic (such as ICMP ping floods or TCP SYN handshake exploits), overloading processing capacity and denying access to legitimate users.
  • Distributed Denial-of-Service (DDoS): An amplified DoS attack launched simultaneously from multiple distributed sources, creating long-term business interruption and severe reputational damage.
  • Zero-Day Attacks: Exploitation of unknown software vulnerabilities by attackers before developers become aware of the security flaw or issue a corrective patch.

5. Conclusion & Professional Responsibilities

As professionals managing critical organizational data and financial reporting, members bear a vital responsibility to protect data confidentiality and maintain operational integrity. Continuous education, security awareness, and vigilant digital practices are essential to counter evolving cyber threats.

References

1. World Telecommunication Development Conference (Kigali, Rwanda, 2022).

2. CyberArk 2023 Identity Security Threat Landscape Report.

3. Indian Ransomware Report (H1-2022) by CERT-In, Ministry of Electronics & IT, Government of India.

4. Cyber Threat Intelligence Advisory Report (August 2023).

Author contact: caganotraanjali@gmail.com | Editorial Board: eboard@icai.in
Published in The Chartered Accountant Journal • September 2024