What the COVID-19 pandemic teaches us about cybersecurity – and how to prepare for the inevitable global cyberattack

cyber

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum. Author: Nicholas Davis, Professor of Practice, Thunderbird School of Global Management and Visiting Professor in Cybersecurity, UCL Department of Science, Technology, Engineering and Public Policy & Algirde Pipikaite, Project Lead, Industry Solutions, Centre for Cybersecurity, World Economic Forum
COVID-19 shows that the world is at great risk of disruption by pandemics, cyberattacks or environmental tipping points.
  • We should prepare for a COVID-like global cyber pandemic that will spread faster and further than a biological virus, with an equal or greater economic impact.
  • The coronavirus crisis provides insights into how leaders can better prepare for such cyber risks.
Most of the world is currently experiencing highly atypical living conditions as a result of COVID-19. At the height of the pandemic, more than 2 billion people were under some form of lockdown, and 91% of the world’s population, or 7.1 billion people, live in countries with border controls or travel restrictions due to the virus.
It would be comforting to think this is merely a “blip” interrupting an essentially stable state of affairs, and that the world will return to “normal” once medicine and science have tamed the virus.
Comforting – and wrong.
 
COVID-19 is not the only risk with the ability to quickly and exponentially disrupt the way we live. The crisis shows that the world is far more prone to disturbance by pandemics, cyberattacks or environmental tipping points than history indicates.
Our “new normal” isn’t COVID-19 itself – it’s COVID-like incidents.
And a cyber pandemic is probably as inevitable as a future disease pandemic. The time to start thinking about the response is – as always – yesterday.
To start that process, it’s important to examine the lessons of the COVID-19 pandemic ­– and use them to prepare for a future global cyberattack.
Lesson #1: A cyberattack with characteristics similar to the coronavirus would spread faster and further than any biological virus.
The reproductive rate – or R0 – of COVID-19 is somewhere between two and three without any social distancing, which means every infected person passes the virus to a couple of other people. This number affects how fast a virus can spread; the number of infected people in New York state was doubling every three days before lockdown.
By contrast, estimates of R0 of cyberattacks are 27 and above. One of the fastest worms in history, the 2003 Slammer/Sapphire worm, doubled in size approximately every 8.5 seconds, spreading to over 75,000 infected devices in 10 minutes and 10.8 million devices in 24 hours. The 2017 WannaCry attack exploited a vulnerability in older Windows systems to cripple more than 200,000 computers in 150 countries; it was halted by emergency patches and the accidental discovery of a “kill switch”.
The cyber equivalent of COVID-19 would be a self-propagating attack using one or more “zero-day” exploits, techniques for which patches and specific antivirus software signatures are not yet available. Most likely, it would attack all devices running a single, common operating system or application.
Since zero-day attacks are rarely discovered right away – Stuxnet used four separate zero-day exploits and hid in systems for 18 months before attacking – it would take a while to identify the virus and even longer to stop it from spreading. If the vector were a popular social networking application with, say, 2 billion users, a virus with a reproductive rate of 20 may take five days to infect over 1 billion devices.
Lesson #2: The economic impact of a widespread digital shutdown would be of the same magnitude – or greater – than what we’re currently seeing.
If cyber-COVID mirrored the pathology of the novel coronavirus, 30% of infected systems would be asymptomatic and spread the virus, while half would continue functioning with performance severely degraded – the digital equivalent of being in bed for a week. Meanwhile 15% would be “wiped” with total data loss, requiring a complete system reinstall. Finally, 5% would be “bricked” – rendering the device itself inoperable.
The end result: millions of devices would be taken offline in a matter of days.
The only way to stop the exponential propagation of cyber-COVID would be to fully disconnect all vulnerable devices from one another and the internet to avoid infection. The whole world could experience cyber lockdown until a digital vaccine was developed. All business communication and data transfers would be blocked. Social contact would be reduced to people contactable by in-person visits, copper landline, snail-mail or short-wave radio.
A single day without the internet would cost the world more than $50 billion. A 21-day global cyber lockdown could cost over $1 trillion.
Total cost impact of 1 day without the internet in the world
Just one day without the internet would cost the world more than $50 billion.
Image: NetBlocks
Cyber lockdown would also introduce novel challenges for digitally dependent economies. During the 2020 Australian bushfires, power outages and damage to mobile phone infrastructure gave citizens a newfound appreciation for battery-operated FM radios. But if cyber-COVID ravaged a country, which radio stations would still operate without digital recording and transmission systems? Would states like Norway, which has completed its transition to digital radio, be able to roll back?
Lesson #3: Recovery from the widespread destruction of digital systems would be extremely challenging.
Replacing 5% of the world’s connected devices would require around 71 million new devices. It would be impossible for manufacturers to rapidly scale up production to meet demand, particularly if manufacturing and logistics systems were affected. For systems that survive, there would be a significant bottleneck in patching and reinstallation.
The geographic concentration of electronics manufacturing would create other challenges. In 2018, China produced 90% of mobile phones, 90% of computers and 70% televisions. Finger-pointing about the source and motive of the cyberattack, as well as competition to be first in line for supplies, would inevitably lead to geopolitical tensions.

What is the World Economic Forum doing on cybersecurity

The World Economic Forum Platform for Shaping the Future of Cybersecurity and Digital Trust aims to spearhead global cooperation and collective responses to growing cyber challenges, ultimately to harness and safeguard the full benefits of the Fourth Industrial Revolution. The platform seeks to deliver impact through facilitating the creation of security-by-design and security-by-default solutions across industry sectors, developing policy frameworks where needed; encouraging broader cooperative arrangements and shaping global governance; building communities to successfully tackle cyber challenges across the public and private sectors; and impacting agenda setting, to elevate some of the most pressing issues.
Platform activities focus on three main challenges:
Strengthening Global Cooperation for Digital Trust and Security – to increase global cooperation between the public and private sectors in addressing key challenges to security and trust posed by a digital landscape currently lacking effective cooperation at legal and policy levels, effective market incentives, and cooperation between stakeholders at the operational level across the ecosystem.Securing Future Digital Networks and Technology – to identify cybersecurity challenges and opportunities posed by new technologies and accelerate solutions and incentives to ensure digital trust in the Fourth Industrial Revolution.Building Skills and Capabilities for the Digital Future – to coordinate and promote initiatives to address the global deficit in professional skills, effective leadership and adequate capabilities in the cyber domain.
The platform is working on a number of ongoing activities to meet these challenges. Current initiatives include our successful work with a range of public- and private-sector partners to develop a clear and coherent cybersecurity vision for the electricity industry in the form of Board Principles for managing cyber risk in the electricity ecosystem and a complete framework, created in collaboration with the Forum’s investment community, enabling investors to assess the security preparedness of target companies, contributing to raising internal cybersecurity awareness.
For more information, please contact us.
How can we prepare for cyber-COVID?
The COVID-19 pandemic provides insight into how leaders can prepare for such a “fat tail” risk:
1. Widespread, systemic cyberattacks are not just possible or plausible; they should be anticipated. As we have seen with COVID-19, even a short delay in the response can cause exponential damage.
2. New Zealand’s success in fighting the pandemic proves that early, decisive actions and clear, consistent communication increase resilience. It’s impossible to prepare for every potential risk, but both the public and private sectors should invest in scenario exercises to reduce reaction time and appreciate the range of strategic options in the event an attack occurs.
3. COVID-19 has revealed the importance of international, cross-stakeholder coordination. Cooperation between public and private sector leaders is also critical, particularly when it comes to mitigation. The Centre for Cybersecurity at the World Economic Forum is just one example of an organization addressing systemic cybersecurity challenges and improving digital trust across institutions, businesses and individuals.
4. Just as COVID-19 has pushed individuals and organizations to look to digital substitutes for physical interactions, government and business leaders should think about the inverse. “Digital roll back” and continuity plans are essential to ensuring organizations can continue to operate in the event of a sudden loss of digital tools and networks, as Maersk learned during the NotPetya cyberattack in 2017, which took out 49,000 laptops and printers and wiped all contacts from their Outlook-synced phones. A necessary part of the digital transformation is having sensitive and important information stored and accessible in physical, printed form.
But perhaps the most important lesson: COVID-19 was a known and anticipated risk. So, too, is the digital equivalent.
Let’s be better prepared for that one.

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

This article is published in association with United Nations.

Guterres warns of ‘wider war’ as Middle East conflict enters second month

The Middle East crisis has lurched into its second month, prompting UN Secretary-General António Guterres to issue a stark warning on Thursday morning that the world is “on the edge of a wider war” with catastrophic global implications. Speaking to the press outside the Security Council in New York, the UN chief painted a grim picture of the rapidly […]
This article is published in association with United Nations.

Middle East war: Energy crunch hits vulnerable nations

The war in the Middle East and the near halt to shipping in the Strait of Hormuz has amplified the energy crunch facing developing nations in Africa and South Asia that rely heavily on imported liquid gas, food and fertilizers.  And with Brent Crude still trading at more than $100 per barrel, many workers and households have reverted to […]
© WHO UN officials in Cyprus oversee the loading of emergency humanitarian supplies for Gaza.

Breaking the Gaza aid bottleneck: 106-tonne delivery arrives via new sea route

This article is published in association with United Nations. The World Health Organization (WHO) has facilitated the delivery of some 106 metric tonnes of lifesaving nutrition supplies to the Gaza Strip – the first shipment via a mechanism to deliver aid by sea, in line with a UN Security Council resolution and amid the ongoing war […]
© IMO Crew members take a break on a ship. (file)

‘No precedent’ for seafarers caught in war zone in post-WW2 era

This article is published in association with United Nations. Some 20,000 seafarers remain stranded on ships in the Strait of Hormuz as the war in the Middle East continues, a situation which has been described as unprecedented in the post-Second World War era. The seafarers are working on some 2,000 ships including oil and gas tankers, […]
© UNIFIL UNIFIL peacekeepers on patrol along the Blue Line in southern Lebanon.

UN condemns killing of two more peacekeepers in Lebanon

This article is published in association with United Nations. The United Nations has condemned two consecutive days of deadly attacks on peacekeepers serving with the UN Interim Force in Lebanon (UNIFIL), amid rising hostilities between Israeli forces and Hezbollah militants.  Two Indonesian peacekeepers were killed on Monday, and two more were injured, in an explosion that hit a UNIFIL logistics convoy, destroying […]
© WFP/Arete/Ali Yunes A building in Beirut lies in ruins after airstrikes in Lebanon.

Middle East war: Attacks on vital healthcare, evacuation strike fears

This article is published in association with United Nations. Almost one month since Israeli and US airstrikes on Iran began, sparking a wider regional war, UN agencies and partners on Friday highlighted the terror among civilians fleeing bombardment, with “no safe space” to go. In a rare piece of good news, though, the UN World Health […]
UN News/Daniel Dickinson The closure of the Hormuz strait is impacting trade on a global scale.

Persian Gulf crisis impacting food security, FAO warns

This article is published in association with United Nations. The intensifying conflict in the Persian Gulf “has triggered one of the most rapid and severe disruptions to global commodity flows in recent times,” the Chief Economist with the UN Food and Agriculture Organization (FAO) said on Thursday.  The crisis is affecting agricultural production and food security worldwide, with impacts […]

Gulf war ‘out of control’, Guterres warns, as UN appoints envoy to push for peace

This article is published in association with United Nations. UN Secretary-General António Guterres has warned that the escalating Gulf war is “out of control”, urging all sides to step back from the brink and allow diplomacy to prevail, as he announced the appointment of a senior envoy to spearhead peace efforts. Speaking outside the UN Security Council in New York […]
This article is published in association with United Nations.

Gaza: Commitment to US-backed plan crucial to recovery, Security Council hears

This article is published in association with United Nations. As tensions escalate in the Middle East, the international community must not lose sight of the situation in Gaza, an official with US President Donald Trump’s Board of Peace across the shattered enclave said on Tuesday in his first appearance in the UN Security Council.  High Representative […]
© IMF/Stephen Jaffe The UN is warning of surging food and fuel prices driven by the escalation of the conflict in the Middle East.

Dire fertiliser shortage a lurking threat due to Hormuz crisis

This article is published in association with United Nations. Since the start of the Middle East conflict with Israeli and US strikes on Iran on 28 February, concerns have been growing over rising oil and commodity prices. At the centre of it lies the Strait of Hormuz – one of the world’s most critical maritime chokepoints […]
© WFP/Arete/Ali Yunes A building in Beirut lies in ruins after airstrikes in Lebanon.

War in the Middle East: Iran nuclear facility hit as equivalent of ‘one classroom of children’ killed, wounded daily in Lebanon

This article is published in association with United Nations. More than 1,000 people have been killed and 2,584 injured in Lebanon since the start of the US-Israel war on Iran, UN officials said Saturday. Key points “Recent escalation has killed or wounded the equivalent of one classroom of children every day,” said Ted Chaiban, deputy chief […]
This article is published in association with United Nations.

Middle East war shockwaves ripple through Asia-Pacific fuel and supply chains

This article is published in association with United Nations. The fallout from the war in the Middle East is rippling far beyond the Gulf, disrupting fuel supplies, shipping routes and supply chains across Asia and the Pacific, with some of the region’s most vulnerable economies already feeling the strain through rising prices, rationing and threats to […]
© WFP/Jaber Badwan A woman carries food rations distributed by the World Food Programme in Almaghazi, Gaza.

Humanitarian needs in Gaza deepen as aid access remains constrained

This article is published in association with United Nations. Humanitarian needs are continuing to grow again across Gaza, the UN agency assisting Palestine refugees (UNRWA) said on Wednesday, amid mounting pressures on aid delivery and the ongoing conflict in the Middle East.  “Families face ongoing hardship” as access to essential aid remains limited and many continue […]
© WFP/Khadija Dia Food is distributed to displaced families sheltering in a school in Tariq Jdide, Beirut.

Middle East war risks pushing 45 million more people into acute hunger

This article is published in association with United Nations. The Middle East war could cause the worst disruption to lifesaving humanitarian work since COVID, the UN World Food Programme (WFP) warned on Tuesday, as the UN chief again demanded an end to the widening conflict. “The Secretary-General asserts once more that the war in the Middle […]
© World Vision Smoke rises in Beit Mery, close to the Lebanese capital, Beirut, following an airstrike.

Middle East war’s ‘spiral of conflict’ drives mounting civilian toll

This article is published in association with United Nations. The widening war in the Middle East and its growing impact on civilians came under scrutiny at the UN in Geneva on Monday, as independent experts briefing the Human Rights Council warned of escalating violence following the onset of Israeli and US strikes on Iran and counterstrikes […]
© Mousawat A mother and child displaced by the conflict in Lebanon receiving care at a clinic.

Middle East war: Women in Lebanon forced to give birth on roadside

This article is published in association with United Nations. As the UN Secretary-General touched down in Beirut on Friday in solidarity with the people of Lebanon, UN agencies highlighted the dangers for civilians and particularly pregnant women and migrant workers, amid ongoing airstrikes and rocket fire between Hezbollah fighters and Israel.  “There’s 11,600 pregnant women who […]
© WFP/Arete/Ali Yunes Some residents of Beirut who have been displaced by the conflict are now living on the streets of the Lebanese capital.

‘Perfect storm’: Lebanon crisis deepens as civilians bear the brunt

This article is published in association with United Nations. Lebanon is facing a “perfect storm of unpredictable challenges” as conflict, mass displacement and dwindling humanitarian resources converge, the UN’s Resident and Humanitarian Coordinator in Lebanon, Imran Riza, has warned. The current escalation began on 2 March, when outgoing fire by Hezbollah drew a strong retaliation from […]
© WFP/Maxime Le Lijour People living in Gaza have received humanitarian aid from the UN throughout the conflict with Israel.

UN relief chief condemns ‘$1 billion-a-day’ cost of war in Middle East

This article is published in association with United Nations. The UN’s emergency relief chief on Wednesday condemned the “$1 billion-a-day” cost of the war in the Middle East, at a time when humanitarian needs are soaring and aid funding is falling dangerously short. “We’re seeing the consequences spread faster than we can respond”, warned the UN emergency […]
© UNICEF/Azizullah Karimi Afghan returnees from Iran gather at the Islam-Border, near Herat in western Afghanistan (file).

‘Toxic rain’ warning from oil depot strikes amid ongoing Middle East war

This article is published in association with United Nations. Toxic “black rain” linked to strikes on oil depots, mass displacement and continuing disruption to aid supply chains are upending lives across the Middle East and beyond after 10 days of war in the region, UN humanitarians said on Tuesday.  Speaking to reporters in Geneva, UN Human […]

Comments

  1. sheena handerson says:

    Thank you for sharing some tips that we can use in shifting our cybersecurity new normal

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com