Cyber Claims Outlook 2024: Trends, Threats, and Tomorrow's Challenges

Unknown

Black Hat USA 2024 · Day 1 · Briefing

Overview

In this insightful Black Hat USA presentation, Katherine Lyle, Head of Cyber Incident Response and Claims at Tokio Marine HCC for CPLG, delivers a comprehensive "Cyber Claims Outlook 2024." Lyle meticulously dissects the evolving landscape of cyber threats, drawing upon a broad dataset that includes government statistics, national insurance data, and insights from forensic providers working with both insured and uninsured entities. The talk moves from a high-level view of market dynamics to granular details of attack vectors and defensive strategies, culminating in critical predictions for the coming years.

Watch on YouTube

Visual summary for Cyber Claims Outlook 2024: Trends, Threats, and Tomorrow's Challenges by Unknown
Visual summary for Cyber Claims Outlook 2024: Trends, Threats, and Tomorrow's Challenges by Unknown

Key moments

  1. 0:00 Introduction and overview of cyber claims market trends.
  2. 2:00 FBI's IC3 report: Phishing and BEC top crimes.
  3. 4:00 Key attack vectors in 2023: Phishing and RDP.
  4. 6:00 2024 attack vectors: VPN without MFA rises significantly.
  5. 7:00 Alarming stagnation in Multi-Factor Authentication (MFA) adoption.

Cyber Claims Outlook 2024: Trends, Threats, and Tomorrow's Challenges

Speakers: Katherine Lyle, Head of Cyber Incident Response and Claims, Tokio Marine HCC for CPLG

Conference: Black Hat USA

YouTube: https://www.youtube.com/watch?v=WcgYT3UakmQ

Overview

In this insightful Black Hat USA presentation, Katherine Lyle, Head of Cyber Incident Response and Claims at Tokio Marine HCC for CPLG, delivers a comprehensive "Cyber Claims Outlook 2024." Lyle meticulously dissects the evolving landscape of cyber threats, drawing upon a broad dataset that includes government statistics, national insurance data, and insights from forensic providers working with both insured and uninsured entities. The talk moves from a high-level view of market dynamics to granular details of attack vectors and defensive strategies, culminating in critical predictions for the coming years.

Lyle's presentation is particularly salient for cybersecurity professionals, risk managers, and business leaders grappling with the financial and operational fallout of cyber incidents. By integrating the perspective of a cyber insurance expert, the talk uniquely bridges the gap between technical vulnerabilities and their real-world economic consequences. It underscores the critical, yet often overlooked, interplay between cyber insurance market health and the efficacy of organizational security postures, providing a vital framework for understanding modern cyber risk.

The core message emphasizes the persistent and evolving nature of cyber threats, highlighting how threat actors adapt to defensive measures and geopolitical shifts. Lyle critically examines the stagnation in the adoption of fundamental security controls like Multi-Factor Authentication (MFA), despite its proven effectiveness. Her analysis serves as a stark reminder that while advanced threats capture headlines, many successful attacks still exploit basic vulnerabilities, making foundational security practices more crucial than ever.

Background

▶ Watch: Introduction and overview of cyber claims market trends. (0:00)

The discussion begins by setting the stage with the broader cyber insurance market trends. Katherine Lyle notes a concerning decrease in stand-alone cyber policy purchases in 2023. While premium growth was observed, this growth was primarily driven by price changes rather than an increase in the number of new buyers. This stagnation in new market entrants is a critical indicator, suggesting that despite the escalating threat landscape, organizations are not proportionally increasing their investment in cyber insurance protection. This trend directly impacts claims, as fewer insured entities could lead to different risk pools and market dynamics.

Lyle's data sources are intentionally diverse and comprehensive, moving beyond a single insurer's perspective to provide a holistic view. She leverages statistics from the FBI's Internet Crime Complaint Center (IC3), national insurance aggregates, Tokio Marine HCC's internal data, and insights from forensic providers who handle incidents for both insured and uninsured organizations. This multi-faceted approach ensures a robust, industry-wide understanding of cybercrime trends.

Looking back at the FBI's IC3 reports, Lyle points out that phishing consistently ranks as the number one reported "crime," though she clarifies it's more accurately described as the primary attack vector. Within these reports, extortion (often synonymous with ransomware) and Business Email Compromise (BEC) also feature prominently. Geographically, states with larger populations and higher concentrations of businesses and older individuals, such as California, Texas, and Florida, report the highest numbers of cyber incidents, highlighting the correlation between opportunity and attack volume.

In 2023, the dominant attack vectors observed by forensic providers echoed the FBI's findings: phishing emails remained the top entry point. Lyle attributes this to its inherent ease and scalability for attackers, noting that "100,000 hackers next door" can effortlessly spam millions of targets, waiting for a single click to establish a foothold. The third most prevalent attack vector in 2023 was Remote Desktop Protocol (RDP), specifically unhidden or exposed instances. Threat actors actively scan the internet for open RDP ports, recognizing them as straightforward entry points to networks, often followed by targeted phishing against the identified organization. This combination of easy initial access methods characterized the cyber threat landscape leading into 2024.

Key Findings

▶ Watch: FBI's IC3 report: Phishing and BEC top crimes. (2:00)

The most significant shift identified in the 2024 outlook is the evolution of primary attack vectors. While phishing remains a persistent threat due to its low barrier to entry and the increasing sophistication aided by tools like ChatGPT for crafting more convincing lures, a new vector has ascended to prominence. VPN without Multi-Factor Authentication (MFA) has moved into the number two position, displacing RDP as a preferred initial access method. This shift is attributed to the expanded attack surface presented by VPNs, especially in a hybrid work environment, and the critical access they provide to internal networks—often described as "the keys to the kingdom." The absence of MFA on these VPNs makes them particularly vulnerable, allowing attackers to leverage stolen credentials for deep network penetration.

A critical and alarming finding presented by Lyle is the stagnation, and even slight regression, in MFA adoption rates across corporations. In 2021, approximately 70% of corporations were not using MFA. While this number improved to 44% in 2023, the trend reversed in 2024, with 45% of organizations still failing to implement MFA. Lyle emphasizes that while MFA is not an impenetrable shield—"if you're a target of choice, sorry"—it acts as a crucial deterrent for opportunistic attackers. She employs the analogy of a "seatbelt" or "fire alarm," explaining that MFA isn't designed to prevent an incident entirely, but rather to prevent "further harm" by delaying or complicating an attacker's progress, often prompting them to move on to easier targets. The speaker also highlights the distinction between simply implementing MFA and actively enforcing it, pointing to a gap where organizations might have the technology but fail to mandate its use.

Another key finding relates to the geopolitical impact on threat actor targeting. Following the imposition of sanctions by the US Treasury Department against certain cybercriminal groups, Lyle observes a noticeable shift in attack patterns. Threat actors are increasingly targeting countries without sanctions, particularly in the Asian-Pacific (APAC) region. This is a direct response to victims informing attackers that they cannot pay ransoms due to sanctions, pushing criminal enterprises to seek out regions where payment is not legally restricted. Lyle predicts this trend will intensify in 2024 and 2025, leading to a rise in cyberattacks against organizations in non-sanctioned geographies.

The discussion also touches upon the varying effectiveness of different MFA classes, such as SMS-based MFA versus authenticator apps or hardware tokens like YubiKeys or smart cards. While acknowledging that "if we want in, we're getting in" for highly determined attackers (the "target of choice"), Lyle reiterates that for the majority of "lazy hackers," any form of MFA, even simpler ones like SMS, can be "just enough" to deter them. This underscores the importance of implementing some MFA rather than none, recognizing that perfect security is often the enemy of good security.

Finally, the talk briefly addresses the issue of dependent system failures, particularly in sectors like healthcare, airlines, and nonprofits. These sectors are often characterized by antiquated technology and budget constraints, making them "lynchpins" whose compromise can have outsized effects across interconnected systems. Lyle praises Google for adopting a "security on by default" approach, contrasting it with Microsoft's historical practice of requiring users to actively enable security features, effectively putting the "seatbelt" in the off position. This highlights a fundamental difference in security philosophy that can significantly impact an organization's baseline protection.

Technical Deep Dive

▶ Watch: Key attack vectors in 2023: Phishing and RDP. (4:00)

The technical deep dive into the current threat landscape, as presented by Katherine Lyle, focuses on the mechanisms and vulnerabilities exploited by the most prevalent attack vectors.

Phishing: This remains the number one attack vector due to its simplicity and effectiveness. Technically, phishing involves attackers sending deceptive communications (emails, messages) designed to trick recipients into revealing sensitive information (like login credentials) or performing actions (like clicking a malicious link or downloading malware). The speaker notes that the rise of Artificial Intelligence (AI) tools, specifically mentioning ChatGPT, has significantly enhanced threat actors' capabilities. AI can generate highly convincing, grammatically correct, and contextually relevant phishing emails at scale, making them harder for human users to detect. This improved fidelity bypasses basic human vigilance and even some traditional email filters that rely on obvious linguistic anomalies. The core technical bypass here is social engineering—exploiting human trust and cognitive biases rather than purely technical flaws.

Remote Desktop Protocol (RDP): In 2023, exposed RDP instances were a significant entry point. RDP is a proprietary protocol developed by Microsoft that allows a user to graphically control a remote computer. When RDP is directly exposed to the internet without proper security controls (like strong, unique passwords and, crucially, MFA), it becomes a prime target. Threat actors use automated scanners to identify systems with open RDP ports. Once an RDP port is found, attackers can attempt brute-force attacks against weak credentials or leverage stolen credentials to gain unauthorized access. The issue is often compounded by default configurations, weak password policies, or misconfigurations that leave these ports unnecessarily open to the public internet, essentially providing a direct graphical interface into a corporate network.

VPN without Multi-Factor Authentication (MFA): This is the ascendant threat for 2024. Virtual Private Networks (VPNs) create a secure, encrypted connection over a less secure network, typically the internet, allowing remote users to access internal corporate resources as if they were physically on the network. The technical vulnerability arises when a VPN solution is configured to rely solely on a single factor of authentication, such as a username and password. If these credentials are stolen (e.g., via phishing, credential stuffing, or breaches of third-party services), the attacker gains immediate, unfettered access to the corporate network through the VPN. This bypasses perimeter defenses and often grants an attacker a high level of privilege, making the VPN without MFA a "key to the kingdom." The "larger landscape" mentioned refers to the proliferation of remote work, leading to more VPN endpoints and, consequently, more potential points of failure if MFA is not enforced.

Multi-Factor Authentication (MFA) Mechanics and Effectiveness: Lyle delves into the nuances of MFA. She distinguishes between simpler forms like SMS-based MFA (where a code is sent to a mobile phone) and more robust methods such as authenticator apps (e.g., Microsoft Authenticator, Google Authenticator) or hardware security tokens (like YubiKeys or smart cards).

  • SMS MFA: While better than nothing, SMS is susceptible to SIM swapping attacks, where an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card controlled by the attacker, thereby intercepting authentication codes.
  • Authenticator Apps: These generate time-based one-time passwords (TOTP) or push notifications. They are generally more secure than SMS as they don't rely on the cellular network for code delivery, making them resistant to SIM swapping. However, push notification fatigue or social engineering can sometimes bypass them.
  • Hardware Tokens (YubiKey, Smart Cards): These are considered the most robust forms of MFA. They typically use cryptographic keys stored on the device and require physical presence or interaction. They are highly resistant to phishing, as the token itself verifies the legitimate site, and nearly impervious to credential theft or SIM swapping.

Lyle's point about "target of choice" versus "lazy hacker" is crucial here. For a highly resourced and determined attacker targeting a specific organization, even advanced MFA can be circumvented through sophisticated techniques like MFA bypass proxies (e.g., Evilginx) or exploiting zero-day vulnerabilities. However, for the vast majority of opportunistic "lazy hackers" who are casting a wide net, encountering any form of MFA, especially robust ones, makes the target less attractive, prompting them to move on to easier prey. The technical "delay" provided by MFA is often sufficient to deter these volume-based attackers.

Finally, the speaker briefly touches on security by default philosophy, contrasting Google's approach with Microsoft's. Google, she notes, often defaults security features to "on," requiring a conscious decision to disable them. Microsoft, historically, has sometimes required users to actively enable security features. This technical default setting has profound implications for an organization's baseline security posture, as many users or administrators may not actively seek out and enable optional security enhancements.

Demo / Proof of Concept

▶ Watch: 2024 attack vectors: VPN without MFA rises significantly. (6:00)

The presentation "Cyber Claims Outlook 2024: Trends, Threats, and Tomorrow's Challenges" by Katherine Lyle was a data-driven analysis and strategic discussion rather than a technical demonstration. As such, no live demo or proof of concept was conducted during the talk.

Defensive Implications

▶ Watch: Alarming stagnation in Multi-Factor Authentication (MFA) adoption. (7:00)

The insights shared by Katherine Lyle carry significant defensive implications for organizations aiming to bolster their cybersecurity posture and manage risk effectively in 2024 and beyond.

  1. Prioritize and Enforce Multi-Factor Authentication (MFA) Universally: The most urgent defensive action is to address the stagnation in MFA adoption. Organizations must move beyond mere implementation to enforcement across all critical systems, especially for VPN access, email, and administrative accounts. While any MFA is better than none, organizations should ideally graduate from SMS-based MFA to more robust methods like authenticator apps or hardware security tokens (e.g., YubiKeys) for high-value targets or privileged users, recognizing their increased resistance to phishing and SIM-swapping. MFA acts as a critical "seatbelt" against opportunistic attackers, significantly reducing the likelihood of successful credential compromise leading to deeper network penetration.
  1. Bolster Phishing Awareness and Technical Controls: Given phishing's continued dominance, robust and continuous employee training is paramount. This training should go beyond basic recognition to include understanding sophisticated AI-generated lures and the dangers of credential harvesting. Technically, organizations should deploy advanced email security gateways with AI/ML-driven detection capabilities to identify and block sophisticated phishing attempts. Implementing DMARC, SPF, and DKIM for email authentication helps prevent email spoofing, a common tactic in BEC and targeted phishing.
  1. Secure Remote Access Points Rigorously: The rise of VPN without MFA necessitates an immediate audit of all remote access solutions. Every VPN endpoint, RDP gateway, and other remote access service must be protected by strong MFA, complex passwords, and ideally, least privilege access principles. Unused or exposed RDP ports should be closed or restricted to authorized IP ranges. Regular vulnerability scanning and penetration testing of these external-facing services are critical to identify and remediate weaknesses before attackers exploit them.
  1. Proactive Supply Chain and Dependent System Risk Management: The mention of "dependent system failures" in sectors like healthcare and airlines highlights the need for a comprehensive supply chain risk management strategy. Organizations must identify their critical third-party vendors and partners, especially those with antiquated technology or limited resources (e.g., nonprofits), and assess their security postures. Applying pressure or collaborating to improve their security, as suggested in the Q&A, can mitigate cascading risks. Focus on understanding the security defaults of critical software and cloud providers, advocating for "security by default" where possible.
  1. Stay Aware of Geopolitical Shifts and Evolving Threat Actor Tactics: The observed shift in threat actor targeting due to sanctions underscores the dynamic nature of cyber threats. Defenders need to monitor geopolitical developments and intelligence reports to anticipate where threat actors might next focus their efforts. Organizations operating in regions not subject to US sanctions, particularly in APAC, should be particularly vigilant and prepare for increased targeting. This also implies understanding that threat actors will adapt their payment methods or preferred targets based on legal and economic pressures.
  1. Adopt a "Security by Default" Mindset: Emulating Google's "security on by default" approach, organizations should strive to configure systems and applications with the strongest security settings from the outset, rather than relying on users or administrators to opt-in to security features. This significantly raises the baseline security posture across the entire enterprise, reducing the attack surface that arises from misconfigurations or unactivated security controls.

By integrating these defensive strategies, organizations can build a more resilient defense against the evolving threats outlined in the 2024 cyber claims outlook, moving beyond reactive incident response to proactive risk mitigation.

Key Takeaways

  • MFA Adoption is Stagnating, Posing Significant Risk: Despite its proven effectiveness as a deterrent, Multi-Factor Authentication (MFA) adoption has stalled, with 45% of corporations still not implementing it in 2024. This leaves organizations highly vulnerable to credential theft and subsequent breaches.
  • VPN without MFA is the New Top Entry Point: While phishing remains prevalent, unsecured VPN access has become the second most common attack vector. Organizations must prioritize strong MFA for all remote access solutions to prevent attackers from gaining "keys to the kingdom."
  • Geopolitical Sanctions Influence Threat Actor Targeting: US sanctions against certain cybercriminal groups are causing a shift in attack patterns, with threat actors increasingly targeting countries not subject to such sanctions (e.g., APAC region) to ensure ransom payments can be processed.
  • MFA Acts as a Crucial Deterrent for Opportunistic Attackers: While not impenetrable for a "target of choice," MFA (even simpler forms) significantly delays and deters "lazy hackers" who will move on to easier targets, making it an essential foundational security control.
  • "Security by Default" is a Superior Philosophy: Software and service providers should adopt a "security on by default" approach, as exemplified by Google, rather than requiring users to manually enable critical security features, which often leads to misconfigurations and increased vulnerability.
  • Supply Chain Vulnerabilities in Antiquated Sectors are Critical: Sectors like healthcare, airlines, and nonprofits, often burdened by legacy technology and budget constraints, represent critical "lynchpins" whose compromise can have widespread systemic impacts, necessitating proactive risk management across the supply chain.

About the Speaker(s)

Katherine Lyle is the Head of Cyber Incident Response and Claims at Tokio Marine HCC for CPLG. In her role, she specializes in analyzing cyber claims, understanding the evolving landscape of cyber threats, and providing strategic insights into market trends. Her expertise spans the intersection of cybersecurity, insurance, and incident response, allowing her to offer a unique perspective on the financial and operational impacts of cybercrime. Lyle is a returning speaker to Black Hat, indicating her recognized authority and continuous engagement with the cybersecurity community on these critical topics.

All talks from Black Hat USA 2024