What if I were to tell you that the threat landscape is changing faster than ever before? According to newly published research from SonicWall, a rather mind-boggling 26.5 new malware variants are being created every hour.
Or, to put it another way, thatโs 637 new, never before seen, malware variants every single day.
Thatโs probably got your attention, but Iโm sorry to report thereโs more to come. Like the fact that 61% of attacks analysed by the SonicWall researchers saw new vulnerabilities being exploited within just two days.ย And encrypted attacks against businesses, created to make detection efforts as difficult as possible, have grown by 80% across 2024.
SMBs are at the sharp end of these attacks, with SonicWall stating that identity, cloud, and credential compromise account for 85% of all actionable alerts.
Thatโs the bad news, but hereโs the worst:ย While threat actors are moving at an unprecedented pace, as that two-day window mentioned earlier shows, โweโre observing that it takes some organisations 120 to 150 days to apply a critical patch,โ SonicWall CEO Bob VanKirk said. โIn 2024,โ VanKirk continued, โwe witnessed alarming trends that underscore the urgent need for proactive defense strategies.โ
SonicWall graphic showing the time it takes for hackers to use new exploit code against businesses
AI driving malware growth
Part of the problem is, as Iโve mentioned here at TechFinitive before, the advances in AI-driven attack methodologies. These are now available to threat actors at a cost that makes them profitable when targeting not just large enterprises but the smaller end of the business market as well.ย
โSMBs are facing a storm of cyber threats, as attackers leverage automation, AI, and advanced evasion techniques to evade traditional defenses,โ the report stated, โas attack surfaces expand and the time to exploit vulnerabilities shrinks, SMBs must prioritise proactive security measures.โ
Given that the SonicWall intelligence found, on average, organisationsย were under critical attack for 68 days, the time to get proactive is long since overdue.
What that means for your business is that simply reacting to incidents after they have occurred really isnโt an option any longer.ย Instead, you need to be actively identifying threats and mitigating them before they can cause you harm.
That means scanning for vulnerabilities and patching systems in a timely fashion, employing a hunter mentality rather than a prey one.
Unless you do that, Iโm afraid youโre doomed to be part of the shocking statistic list next year.
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.