Connect with us

E-Business

IT Managers are Inundated with Cyberattacks, Struggling to Keep Up, Says Sophos Global Survey

Published

on

Kindly share this post

Sophos, a global leader in network and endpoint security, has announced the findings of its global survey, The Impossible Puzzle of Cybersecurity, which reveals that IT managers are inundated with cyberattacks coming from all directions and are struggling to keep up due to a lack of security expertise, budget and up to date technology.

 

The survey polled 3,100 IT decision makers from mid-sized businesses in the US, Canada, Mexico, Colombia, Brazil, UK, France, Germany, Australia, Japan, India, and South Africa.

 

Cybercriminals Use Multiple Attack Methods and Payloads for Maximum Impact

Advertisement

The Sophos survey shows how attack techniques are varied and often multi-staged, increasing the difficulty to defend networks.

 

One in five IT managers surveyed didn’t know how they were breached, and the diversity of attack methods means no one defensive strategy is a silver bullet.

 

“Cybercriminals are evolving their attack methods and often use multiple payloads to maximize profits. Software exploits were the initial point of entry in 23 percent of incidents, but they were also used in some fashion in 35 percent of all attacks, demonstrating how exploits are used at multiple stages of the attack chain,” said Chester Wisniewski, principal research scientist, Sophos.

Advertisement

 

“Organizations that are only patching externally facing high-risk servers are left vulnerable internally and cybercriminals are taking advantage of this and other security lapses.”

 

The wide range, multiple stages and scale of today’s attacks are proving effective. For example, 53 percent of those who fell victim to a cyberattack were hit by a phishing email, and 30 percent by ransomware. Forty-one percent said they suffered a data breach.

 

Advertisement

Weak Links in Security Increasingly Lead to Supply Chain Compromises

 

Based on the responses, it’s not surprising that 75 percent of IT managers consider software exploits, unpatched vulnerabilities and/or zero-day threats as a top security risk.

 

Fifty percent consider phishing a top security risk.

Advertisement

 

Alarmingly, only 16 percent of IT managers consider supply chain a top security risk, exposing an additional weak spot that cybercriminals will likely add to their repertoire of attack vectors.

 

“Cybercriminals are always looking for a way into an organization, and supply chain attacks are ranking higher now on their list of methods. IT managers should prioritize supply chain as a security risk, but don’t because they consider these attacks perpetrated by nation states on high profile targets. While it is true that nation states may have created the blueprints for these attacks, once these techniques are publicized, other cybercriminals often adopt them for their ingenuity and high success rate,” said Wisniewski.

 

Advertisement

“Supply chain attacks are also an effective way for cybercriminals to carry out automated, active attacks, where they select a victim from a larger pool of prospects and then actively hack into that specific organization using hand-to-keyboard techniques and lateral movements to evade detection and reach their destination.”

 

Lack of Security Expertise, Budget and Up to Date Technology

According to the Sophos survey, IT managers reported that 26 percent of their team’s time is spent managing security, on average.

 

Advertisement

Yet, 86 percent agree security expertise could be improved and 80 percent want a stronger team in place to detect, investigate and respond to security incidents.

 

Recruiting talent is also an issue, with 79 percent saying that recruiting people with the cybersecurity skills they need is challenge.

 

Regarding budget, 66 percent said their organization’s cybersecurity budget (including people and technology) is below what it needs to be.

Advertisement

 

Having current technology in place is another problem, with 75 percent agreeing that staying up to date with cybersecurity technology is a challenge for their organization.

 

This lack of security expertise, budget and up to date technology indicates IT managers are struggling to respond to cyberattacks instead of proactively planning and handling what’s coming next.

 

Advertisement

“Staying on top of where threats are coming from takes dedicated expertise, but IT managers often have a hard time finding the right talent or don’t have a proper security system in place that allows them to respond quickly and efficiently to attacks,” said Wisniewski.

 

“If organizations can adopt a security system with products that work together to share intelligence and automatically react to threats, then IT security teams can avoid the trap of perpetually catching up after yesterday’s attack and better defend against what’s going to happen tomorrow.

 

“Having a security ‘system’ in place helps alleviate the security skills gap IT managers are facing. It’s much more time and cost effective for businesses to grow their security maturity with simple to use tools that coordinate with each other across an entire estate.”

Advertisement

 

Synchronized Security Solves the Impossible Puzzle of Cybersecurity

 

With cyberthreats coming from supply chain attacks, phishing emails, software exploits, vulnerabilities, insecure wireless networks, and much more, businesses need a security solution that helps them eliminate gaps and better identify previously unseen threats.

 

Advertisement

Sophos Synchronized Security, a single integrated system, provides this much needed visibility to threats by integrating Sophos endpoint, network, mobile, Wi-Fi, and encryption products to share information in real-time and automatically respond to incidents. More information about Synchronized Security is available at Sophos.com.

 

The Impossible Puzzle of Cybersecurity survey was conducted by Vanson Bourne, an independent specialist in market research, in December 2018 and January 2019.

 

This survey interviewed 3,100 IT decision makers in 12 countries and across six continents in the US, Canada, Mexico, Colombia, Brazil, UK, France, Germany, Australia, Japan, India, and South Africa. All respondents were from organizations with between 100 and 5,000 employees.

Advertisement

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

Published

on

Kindly share this post

Pan-African digital rights organisation Paradigm Initiative (PIN) has warned that violent extremist groups are increasingly exploiting digital platforms to recruit, radicalise and manipulate young people across the Sahel region.

Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

The organisation raised the concern in a new policy brief titled “Digital Frontlines: Countering Online Radicalisation and Violent Extremist Narratives in the Sahel.”

According to the publication, extremist groups are shifting from traditional recruitment methods to digital platforms, including social media, encrypted messaging applications, short-form video platforms and online financial incentives, to target vulnerable populations.

PIN noted that unemployed youths and people facing insecurity and limited economic opportunities are particularly susceptible to online recruitment campaigns.

The organisation said that although governments have intensified efforts to combat violent extremism, responses to the digital dimension of the threat have failed to keep pace with rapidly evolving online tactics.

Advertisement

It argued that addressing online radicalisation requires more than surveillance and restrictive measures, recommending investments in digital literacy, stronger community resilience, improved early-warning systems and credible counter-narratives.

PIN also urged governments to work closely with technology companies and civil society organisations to disrupt extremist recruitment while protecting citizens’ digital rights.

The report further highlighted the growing convergence between organised crime and violent extremist groups, noting that online propaganda increasingly promises financial rewards, belonging and purpose to vulnerable young people.

According to the organisation, this trend underscores the need for policymakers to prioritise prevention alongside conventional security responses.

Speaking on the findings, Moussa Waly SENE, Programmes Officer for Francophone Africa at Paradigm Initiative, described the digital space as a new frontline in the fight against violent extremism.

Advertisement

“As more young Africans come online, stakeholders must ensure that digital platforms remain spaces for opportunity, innovation and civic participation, not recruitment grounds for violent extremist groups. Protecting digital rights and protecting vulnerable communities should be mutually reinforcing objectives,” he said.

Among its recommendations, the policy brief called for stronger regional cooperation to tackle cross-border online extremist networks, rights-respecting content moderation and greater accountability by digital platforms.

It also advocated expanded digital literacy programmes to strengthen resilience against online manipulation and community-led initiatives that empower young people to identify and reject extremist narratives.

The organisation further urged policymakers to develop security measures that balance national security objectives with the protection of privacy, freedom of expression and access to information.

Advertisement

Kindly share this post
Continue Reading

E-Business

Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

Published

on

Kindly share this post

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users.

The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer.

It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.

In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT)  identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities.

One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.

Advertisement

Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.

The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.

The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.

“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.

Advertisement

Kindly share this post
Continue Reading

E-Business

Firm to recruit over 100 professionals to boost NRS e-Invoicing compliance

Published

on

Kindly share this post

Afri Invoice, one of Nigeria’s leading accredited e-invoicing service providers, has announced plans to recruit more than 100 professionals nationwide to strengthen support for the Nigeria Revenue Service’s (NRS) mandatory e-invoicing compliance programme.

The recruitment campaign, is aimed at expanding the company’s workforce to meet the growing demand for digital tax infrastructure and help businesses transition smoothly to the country’s evolving e-invoicing regime.

According to the company, the new positions will be spread across Nigeria’s six geopolitical zones to ensure businesses receive timely, localised support as they adapt to the new tax compliance framework.

The vacancies cut across several key departments, including Information Technology (IT), Marketing and Digital Marketing, Audit, Legal, Human Resources and multi-site office operations.

Afri Invoice said applicants are expected to possess relevant professional experience, particularly in managing operations across multiple locations and supporting organisational growth.

Advertisement

The company explained that the latest recruitment drive builds on a similar exercise conducted last year, which significantly expanded its operational reach and increased its capacity to onboard clients nationwide.

With the NRS intensifying the implementation of mandatory e-invoicing, Afri Invoice said it is investing in additional manpower to ensure uninterrupted service delivery, efficient client onboarding and expert technical support for businesses of all sizes.

Speaking on the expansion, the Founder and Chief Executive Officer of Afri Invoice, Mark Odenore, said the company remains committed to helping Nigerian businesses comply with the new tax regulations through innovative technology and professional support.

“As the national drive toward comprehensive e-invoicing gathers momentum under the Nigeria Revenue Service, our mission is to ensure that Nigerian businesses have a reliable, accredited partner to navigate this transition effortlessly,” Odenore said.

He added that recruiting more than 100 professionals across the country’s geopolitical zones would significantly strengthen the company’s ability to provide quality technology solutions and customer support nationwide.
Interested and qualified candidates have been encouraged to submit their applications through Afri Invoice’s official careers portal.

Advertisement

Afri Invoice is an accredited e-invoicing service provider that offers digital solutions designed to simplify financial processes, improve tax transparency and support businesses in complying with national tax regulations while enhancing supply chain and financial management.

Kindly share this post
Continue Reading

Trending