5
Min Read
June 5, 2025

Cybercrime and Ransomware: A Massively Growing Problem

Top 3 CISO Challenges in Cybersecurity: Part 1

Rob Musquetier
Rob Musquetier
Senior Consultant - Cyber Defence
Cybercrime and Ransomware: A Massively Growing Problem

What are the main cybersecurity challenges for CISOs? How do cybercriminals infiltrate your organization? What are the priorities and what can the CISO do? Cybersecurity expertRob Musquetier identified the top 3 priorities for CISOs and provides practical CISO tips. This first part explains the biggest challenges for CISOs: cybercrime, ransomware, and penetration techniques.

Cybercrime, Ransomware, and Penetration Techniques

By far the biggest challenge for CISOs is cybercrime and preventing ransomware. Cybercriminals try to inflict as much damage as possible. With the deployment of Artificial Intelligence (AI), cybercriminals also have more and more means to cause damage than before. Cybercriminals can, with just a few punchy prompts assemble a complete arsenal to shut down organizations and steal data. While CISOs have to resolve about a hundred new vulnerabilities weekly, hackers only need one or two weak spots to carry out a successful attack and hold your organization hostage.

Cybercriminals use various techniques to infiltrate systems. They infiltrate by exploiting:

  1. Publicly accessible systems;
  1. External services with access to your network or system;
  1. Attacks using fake emails, app, SMS, and phone messages;
  1. Trusted relationships;
  1. Valid accounts.

By using a combination of data and with the help of AI, cybercriminals appear credible, and deception becomes easier.  

How can a CISO prevent ransomware?

The CISO can prevent ransomware attacks by cybercriminals by following these five tips.

Tip 1: Basic knowledge upon hiring, systems, and measures

Explain to new employees which vulnerabilities apply to the organization, as well as to the performance of their specific role. During onboarding, it's important to concretely explain how employees should handle vulnerabilities and which measures are applicable to prevent incidents and data breaches. Also, make employees aware that anything with a chip and/or that can connect to the internet is a potential target for cybercriminals. Almost all company assets such as access cards and systems (fobs, tags), phones, passes, laptops, business systems, (medical, industrial) equipment, modern cars, et cetera have a chip.  

Because cyber risks are often abstract and difficult to imagine, it helps to provide relevant examples for one's own industry.

Tip 2: Apply the appropriate checks for privacy protection, IT security, and risk management with suppliers and (sub)processors

Check suppliers and (sub)processors for compliance prior to collaboration. This is also necessary when purchasing equipment and systems with computer chips. The CISO, Privacy Officer, and potentially the Data Protection Officer must always be involved in a procurement and/or tendering process.  

Some examples:

Tip 3: Access control for buildings and areas

Sabotage can also occur through a (legal) intruder who, once inside, corrupts systems. Good policy and management regarding employees and visitors reduce the chance of unwanted intruders. Therefore, ensure strict processes for:

  • Verification of the identity of new and hired employees;
  • Verification of employee integrity; conduct a thorough integrity check before employment or hiring;
  • Issuance of tags and access rights to buildings and specific areas;
  • Visitors; have visitors register in advance and do not leave them unattended;
  • Piggy backers (tailgaters), teach people not to let anyone in without registration.

Tip 4: Access control for business systems and information

Good policy and management help prevent misuse. Ensure clear processes for:

  • Verification of employee identity upon hiring;
  • Verification of the correct employee when issuing company equipment;
  • Access to business systems upon hiring, change of function/role, and termination of employment.  

Tip 5: Up-to-date Awareness Training

Thanks in part to AI, the quality of sabotage campaigns is improving, and they are increasingly cross-media. People then receive credible-looking calls to action at or around the same time through various channels such as email, SMS, app, and phone. To prevent employees from (accidentally) enabling ransomware attacks by, for example, clicking on a wrong link, it is good to stay informed about the latest developments and regularly update awareness training.

Conclusions on Cybercrime and Ransomware

Ransomware attacks are regularly successful for cybercriminals and involve enormous sums of money. It is expected that combating cybercrime and cyberattacks will remain the top priority for CISOs in the coming years. Of course, as a CISO, you can't prevent everything or foresee every threat, but you can learn from others' experiences, and you'll certainly sleep much better if your defenses are in order!

Also read the other two parts on the Top 3 CISO Challenges in Cybersecurity:

Part 2: Quality of Fake Emails

Part 3: Limited Budget and CISO Mandate

Questions about cybersecurity? Ask Navaio! Navaio - Contact
Stel ons jouw vraag!
Thank you! You have been subscribed.
Oops! Something went wrong while submitting the form.
Download E-Book Unravelling UGC: A Comprehensive Exploration