Focusing on the “pre-attack” or “planning” stages of cyber threats — which requires actively gathering intelligence from the dark web — is key for cybersecurity, dark web intelligence firm Searchlight Cyber said in a report published on Wednesday.
“This stage is critical for cybersecurity professionals because it is the only part of the attack that takes place off their infrastructure. If they can spot threat actors targeting them in this phase, they can prevent them from ever reaching their network in the first place,” the report said.
In a survey of over a thousand CISOs (chief information security officers) in the U.S. and UK, Searchlight Cyber found a “clear correlation between the CISOs that are gathering threat intelligence, pre-attack intelligence, and gathering data from the dark web.”
Organizations that invest in dark web intelligence are more confident in their understanding of adversaries and are more likely to identify a threat in the pre-attack phase, the report said.
Why Dark Web Intelligence is Key
According to Searchlight Cyber, applying dark web intelligence allows organizations to identify historic breaches, hunt for threats, monitor risks in their supply chains, and generally be more proactive in safeguarding their security.
Dark web intelligence “should be drawn into the security operations center and cross-referenced against other intelligence sources to identify the most pressing threats based on the pre-attack activity of criminals,” Searchlight Cyber said.
However, there is work to be done as over a fifth of CISOs “have no threat intelligence at all,” the report said, adding that 76 percent of CISOs use some variant of threat intelligence in their security strategy. But this is not necessarily the proactive intelligence Searchlight Cyber recommends for large organizations.
A vast majority of the respondents (93 percent) told Searchlight Cyber they were concerned about dark web threats, while 72 percent said dark web intelligence is “critical” for securing their organizations.
Nearly 80 percent of the respondents told Searchlight Cyber that they currently monitor the dark web for leaked data, supply chain risk data, information about software or hardware vulnerabilities, and intelligence on major threat groups.
“In terms of how they gather this data, CISOs reported that they used a dark web intelligence platform, followed by feed, and a consultant service provider,” the report said.
Only 24 percent of the CISOs who participated in the survey have a dedicated threat intelligence team. Even more worrying, a fifth of respondents said they do not believe cybercrime can affect their business, while 18 percent said they have difficulties finding the link between cyberattacks and the dark web.
Differences Across the Pond and Fields
Searchlight Cyber’s survey revealed that more CISOs in the U.S. are gathering intelligence from the dark web compared to CISOs from the UK. The survey also revealed differences in the way CISOs from the U.S. and UK perceive dark web intelligence.
“69 percent of US CISOs understand that criminal activity on the dark web can have an impact on their company, compared to 59 percent in the UK,” the report said. CISOs in the U.S. are also more aware of the need for threat intelligence and are more interested in defending their supply chain than their UK counterparts.
“Most significantly, US enterprises are more than 20 percentage points more likely to identify a threat before it hits their network (54 percent vs 75 percent),” the report said, proving the value of pre-attack intelligence.
Across sectors, the finance sector has widely adopted dark web intelligence and is thought to be the most “cyber mature,” followed by IT & telecoms, manufacturing, and professional services.
Sadly, the healthcare industry is behind by over 20 percent in threat intelligence, the report said. Similarly, oil and gas businesses are below average and, like the healthcare sector, display “a lack of understanding of where cyberattacks against their enterprises are originating.”
Ben Jones, the CEO of Searchlight Cyber, noted that the cybersecurity landscape has changed significantly over the past few years.
“Cybercriminals are no longer just focusing on asset-rich organizations like banks and insurance companies. They are increasingly targeting enterprises in industries such as healthcare, oil and gas, and manufacturing, and leveraging the critical nature of these companies to extort ransoms,” he said.
Jones highlighted examples of high-profile attacks, such as the U.S. colonial pipeline attack, adding that Searchlight Cyber has observed threat actors compromising VPNs to attack critical industrial sectors.
“Visibility into this cybercriminal reconnaissance would help CISOs in the healthcare and oil and gas sector to identify likely paths of attack, inform defenses, and help them prioritize imminent threats,” he said.
Searchlight Cyber’s Director of threat intelligence Jim Simpson laid out some recommendations for large organizations, which include using dark web intelligence, building threat models, and utilizing the MITRE ATT&CK Framework.
Looking to start gathering intelligence from the dark web? Check out our guide to safely accessing the dark web.
