-

DirectDefense Reports the Top Threats from 2022 and What’s Trending for 2023

Research found that phishing threats were low in 2022, while foreign login activity and application process analysis accounted for nearly 50% of incident alerts

DENVER--(BUSINESS WIRE)--DirectDefense, Inc., an information security services company, today released its “Security Operations Threat Report” which identifies the top threats in 2022 and what’s already trending for 2023. Using its proprietary ThreatAdvisor software, DirectDefense evaluated the managed services activities logged for its clients last year.

Of the hundreds of thousands of alerts managed, DirectDefense investigated 100% of them and acted on or dismissed 77% so that only 23% needed client collaboration to close the event, saving over 1.1 million hours in alert investigation time for clients while providing 7x24x365 monitoring. There were seven threat types identified by the DirectDefense team, including custom alerts created by DirectDefense based on our clients’ unique needs and program support. Outside of custom alerts, foreign login activity and process analysis (suspicious application processes) represented almost 50% of the threats identified.

  • Custom Alerting - 30%
  • Foreign Login Activity - 27%
  • Process Analysis - 21%
  • Account Activity - 9%
  • Phishing Attempts - 7%
  • Mailbox Manipulation - 5%
  • Deceptive Technologies - 1%

Surprisingly, phishing accounted for a low number of client alerts. This infrequency could be the result of tighter organizational email security protocols or simply fewer phishing attempts overall due to previous year’s events where threat actors scraped email addresses and personal information from social networking sites and took other approaches, like brute force attacks. It’s worth noting that of the 7% phishing attempt alerts, 859 were positive phishing attempts and three of those escalated to an incident response engagement.

In 2022, DirectDefense spent nearly 30,000 hours on event triage, with approximately 7,600 hours attributed to level 1 / initial analysis and 21,700 to level 2 / secondary analysis and action.

Each DirectDefense SOC analyst spent an average of 1,723 hours on event triage and response.

“The number of hours spent investigating alerts, many of which require no action, can stop productivity in its tracks. Not to mention how alert fatigue often results in simply not investigating alerts, thereby potentially missing a very real threat – and the opportunity to respond quickly,” said Jim Broome, President and Chief Technology Officer for DirectDefense. “Even when companies elect to handle certain alerts in-house, the benefit of having 100% of alerts immediately investigated by an MSSP removes a significant strain on organizational resources.”

In looking at 2023, the DirectDefense team identified four primary threats that top the list for security concerns.

  • Ransomware: A serious threat facing organizations, the most common infiltration techniques for ransomware include supply chain attacks, data exfiltration to a separate location, Ransomware as a Service (RaaS) / pay-for-use malware platforms, out-of-date system patches, and phishing. Operational disruptions, data compromise and loss, and reputational damages are top concerns in any security breach, especially ransomware.
  • Cloud infrastructure attacks: A high incidence of cloud infrastructure attacks occurred because clients were allowing their developers to run a development cloud environment with little to no production controls oversight. Organizations need to ensure they have configuration requirements and service hardening procedures in place for all cloud environments, not just production.
  • Blind by design applications: There are many applications that don’t offer even the most basic security controls or audit logs. These blind-by-design applications are leaving organizations open to attack, and closing these gaps requires application testing for function and logic vulnerabilities, authentication mechanisms, room for abuse, and logging quality.
  • Emerging AI (ChatGPT): The threat from ChatGPT is far different than headlines suggest. Right now, AI is just a tool that can be used by both malicious actors and well-intentioned individuals. DirectDefense expects to see an increase in social engineering and phishing attacks using information from ChatGPT to execute.

The full report can be found at: https://go.directdefense.com/2022-Security-Operations-Threat-Report.

Follow DirectDefense

LinkedIn: https://www.linkedin.com/company/directdefense/
Twitter: https://twitter.com/Direct_Defense
Blog: https://www.directdefense.com/resources/blog/

About DirectDefense, Inc.

DirectDefense provides enterprise risk assessments, penetration testing, ICS/SCADA security services, and 24/7 managed security services for companies of all sizes. Focused on building security resiliency, the firm offers comprehensive security testing services with specialization in application security, vulnerability assessments, penetration testing, and compliance assurance testing. Its team of highly talented consultants has worked with the majority of the Fortune 100 companies, in industries such as power and utility, gaming, retail, financial, media, travel, aerospace, healthcare, and technology. More information can be found at www.directdefense.com.

Contacts

Cathy Summers
Summers PR
cathy@summers-pr.com
415-483-0480

DirectDefense, Inc.

Details
Headquarters: Englewood, CO
CEO: Jim Broome
Employees: 100
Organization: PRI

Release Versions

Contacts

Cathy Summers
Summers PR
cathy@summers-pr.com
415-483-0480

More News From DirectDefense, Inc.

Matt Maddox Joins DirectDefense as Vice President of Professional Services

DENVER--(BUSINESS WIRE)--DirectDefense, a leading information security services company, today announced that Matt Maddox has joined the company as Vice President of Professional Services. In this role, Maddox will lead DirectDefense’s growing portfolio of industry-leading security services, including web application, network, cloud, API, thick client, mobile, OT, and embedded systems penetration testing. Maddox brings more than 20 years of technical and leadership experience building high-perf...

DirectDefense Launches Security Essentials, Enterprise-Grade Cybersecurity for SMBs at a Fraction of the Cost

DENVER--(BUSINESS WIRE)--DirectDefense, Inc., an information security services company, today launched DirectDefense Security Essentials, a fully managed, subscription-based security program purpose-built for small to mid-sized businesses (SMBs). With Security Essentials, DirectDefense is addressing the critical security needs of the underserved SMB market by combining virtual CISO (vCISO) services, identity threat protection, and vulnerability management at a price point designed for growing b...

DirectDefense Releases Annual Security Operations Threat Report Identifying Top Attack Tactics and Emerging Threats for 2025

DENVER--(BUSINESS WIRE)--DirectDefense, Inc., an information security services company, today released its “2025 Security Operations Threat Report” which identifies the type and frequency of threats, offers insight into attacker behavior and the evolution of security threats, and forecasts the biggest threats to be aware of for the remainder of 2025. In 2024, DirectDefense processed more than 10 million log events, ensuring rapid detection, response, and mitigation of potential cyber threats. T...
Back to Newsroom