What is a cyber attack?
A cyber attack is an attempt to gain unauthorised access to systems, data or accounts in order to steal, destroy, extort or disrupt operations. Where cybersecurity is the discipline that protects you, the cyber attack is the very event you are protecting yourself against. The Danish Centre for Cyber Security assesses the threat from cybercrime against Danish businesses as very high, and most attacks are automated: attackers look for open doors, not for specific victims.
The most common attack types
- Phishing and CEO fraud: Fake emails and messages, often with spoofing of the sender address, that trick employees into giving up login credentials or making payments. The vast majority of attacks start here.
- Ransomware: The attacker encrypts your data using malware and demands a ransom, typically combined with a threat to leak data.
- DDoS attacks: Your webshop or systems are flooded with traffic until they go down. Used both for extortion and as a diversion.
- Compromised accounts and supply chains: A stolen password or an attack on your IT supplier gives the attacker legitimate access that is hard to detect.
How a typical cyber attack unfolds
Serious attacks rarely happen in a single click. First, the attacker gains access through a deceived employee or an unpatched vulnerability. Privileges are then escalated, ideally all the way to administrator accounts. The attacker then spreads quietly through the network, maps backups and business-critical systems and steals data along the way. Only at the end does the attack become visible, often with encryption and an extortion demand, at a moment when the damage is greatest, for example during the night before a public holiday.
What determines the extent of the damage?
Three factors separate the companies that escape with a scare from those facing weeks of downtime: how quickly the attack is detected (the longer the attacker has had access, the deeper they are entrenched), whether a tested backup exists that the attacker could not reach, and whether a rehearsed contingency plan is in place, so the first 24 hours are spent on containment instead of panic. For many businesses, NIS2 also imposes formal requirements on precisely incident handling and reporting.
How to prevent cyber attacks
Four measures remove the majority of the risk: MFA on all accounts, rapid rollout of security updates, ongoing awareness training for employees and a written, tested contingency plan. If you want to go deeper into attacks and defence, we have written an article on cyber attacks and defence, and the management perspective is gathered in the e-book The executive's guide to IT security.
How MI Support IT helps
We prevent cyber attacks through regular security reviews, hardening, monitoring and awareness training as part of IT security, and we help you prepare for the worst through an IT contingency plan. Contact us if you want to know where your business stands, before the attackers test it for you.