The Cisco Annual Security Report 2018 highlights the huge growth in the complexity and impact of malware used in cyber attacks. It also identifies the common use of encryption to enhance security is being used by malicious actors as a powerful tool to conceal command-and-control (C2) activity. With this reduction in visibility, organisations are increasingly using machine learning and AI to spot unusual patterns in large volumes of encrypted web traffic.
Technically accurate and highly regarded
The Cisco Annual Security Report is highly regarded for its accurate forecast of future cyber attack methodologies. This is a result of the inclusion of data from several global surveys and the views of Cisco’s own security teams and partners such as Qualys, Radware and Anomali.
The 2018 report also highlights findings from the Cisco 2018 Security Capabilities Benchmark Study, which examines the security posture of enterprises and their perceptions of their preparedness to defend against attacks.
More new self-propagating network threats in 2018
2017 was the year of the self-propagating ransomware worm and the report does a great job of summarising the impact of WannaCry and Nyetya. It also notes that both infections could have been prevented if more organisations had applied basic security best practices such patching vulnerabilities, network segmentation and having more effective incident response plans.
Malicious encrypted web traffic
Cisco confirms that 50% of global web traffic was encrypted as of October 2017. Encryption is considered essential for cyber security and has been widely supported by the increase in the availability of low-cost or free SSL certificates. Businesses are also motivated to comply with Google’s HTTPS encryption requirement unless they want to risk a potentially significant drop in their Google search page rankings.
Rise of artificial intelligence
Over a third of the security professionals surveyed confirmed that they rely on machine learning and use endpoint and managed detection & response (MDR) technology to spot potential attacks. Roughly half of these organisation employ the services of an outsourced Managed Security Service Provider (MSSP).
DDoS burst attacks grow in frequency and duration
A Distributed Denial of Service (DDoS) attack is an attempt to make an online service unavailable by overwhelming it with traffic from multiple sources. Radware observed a significant increase in short-burst DDOS attacks with a complex, frequent, and persistent pattern.
Email remains a dominant attack vector
Of the malicious domains analysed, about 60 percent were associated with spam email campaigns. Phishing and spear phishing are well-worn and very effective tactics for stealing users’ credentials and other sensitive information. Phishing emails were at the root of some of the biggest, headline-grabbing breaches in 2017 that included a widespread attack on Gmail users and a hack of the Irish Energy systems.
Increasing use of cloud to improve security
53% of defenders surveyed confirmed that they manage their IT infrastructure in the cloud. Outside of the cost and flexibility advantage, all stated that improving cyber security was a key factor in this decision.
Internet of Things (IoT) present new attack surfaces
IoT devices and related cloud services are being deployed at a rapid pace particularly in Operational Technology (OT) systems. However, unpatched and unmonitored IoT devices present attackers with new opportunities to infiltrate networks. 31% of security professionals confirmed they have already experienced cyber attacks on their OT (particularly Industrial Control System) infrastructure.
The Cisco Annual Security Report 2018 is a an essential ‘must read’ guide for all cyber security professionals. I can also highly recommend its Executive Summary to interested non-technical managers who are looking for a concise and accurate summary of the cyber security challenges faced by all organisations in the future.


