The State of Cybersecurity – Year in Review
RSA Conference 2024 · West Stage Keynote
Overview
Kevin Mandia, CEO of Mandiant at Google Cloud, delivered a concise yet comprehensive overview of the cybersecurity landscape based on over 1,100 investigations, hundreds of red team exercises, extensive threat intelligence, and advisory services conducted over the past year. His presentation at RSAC 2024 synthesized these vast datasets into five critical conclusions, highlighting both the escalating sophistication of offensive cyber operations and the encouraging advancements in defensive strategies and public-private partnerships. Mandia's talk serves as a vital compass for understanding the evolving threats and the necessary strategic shifts required to protect global enterprises.

Key moments
- 0:00 Introduction and talk agenda
- 1:00 Overview of 5 key cybersecurity conclusions
- 3:00 Proposed solutions to deter cybercrime
- 4:30 Sharp rise in zero-day exploits observed
- 6:10 Exploitation replaces phishing as top attack vector
- 7:10 Chinese espionage leads in zero-day exploitation
The State of Cybersecurity – Year in Review
Speakers: Kevin Mandia, CEO Mandiant Google Cloud
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=rFMmDvwxaEs
Overview
Kevin Mandia, CEO of Mandiant at Google Cloud, delivered a concise yet comprehensive overview of the cybersecurity landscape based on over 1,100 investigations, hundreds of red team exercises, extensive threat intelligence, and advisory services conducted over the past year. His presentation at RSAC 2024 synthesized these vast datasets into five critical conclusions, highlighting both the escalating sophistication of offensive cyber operations and the encouraging advancements in defensive strategies and public-private partnerships. Mandia's talk serves as a vital compass for understanding the evolving threats and the necessary strategic shifts required to protect global enterprises.
The talk underscored a stark reality: the perceived low risk for threat actors fuels an accelerating innovation in offensive capabilities, particularly in the realm of zero-day exploits. This environment has seen ransomware evolve beyond data encryption to sophisticated data theft, extortion, and even harassment, escalating the pressure on organizations. Simultaneously, Mandia noted an unprecedented level of engagement from corporate boards in cybersecurity governance, driven by regulatory changes and high-profile incidents. Crucially, the presentation also celebrated a significant improvement in the partnership between government and the private sector, fostering a more collaborative and effective defense ecosystem.
Mandia's insights provide a critical reality check for cybersecurity professionals, emphasizing the need for proactive defense, robust incident response, and a fundamental shift in how organizations approach security. By dissecting the latest trends in attack vectors, threat actor methodologies, and defensive improvements, the talk offers actionable intelligence for defenders striving to stay ahead in an increasingly complex and dangerous digital world.
Background
▶ Watch: Introduction and talk agenda (0:00)
The cybersecurity landscape has been in constant flux, but the past year, as observed by Mandiant, represents a significant inflection point characterized by rapid changes in both offensive and defensive postures. The foundation of Mandia's analysis rests on a massive dataset accumulated from Mandiant's frontline incident response, proactive red teaming, and deep threat intelligence capabilities. This includes data from over 1,100 investigations and insights from Google's Threat Analysis Group (TAG), offering a panoramic view of global cyber activity.
Historically, the cybersecurity community has grappled with persistent challenges such as spear phishing as a primary initial access vector and a relatively static number of identified zero-day exploits. Mandia highlighted a historical trend from 1998 to approximately 2019 where spear phishing and exploiting human trust were the most common infiltration methods. However, this has dramatically shifted since 2020, reverting to an older paradigm (1993-1998) where direct exploitation, particularly of vulnerabilities, dominates. This shift indicates a maturing attacker toolkit and a potential increase in the impact and funding behind offensive operations.
The evolution of ransomware also forms a crucial part of this background. What began primarily as encryption for financial gain has morphed into a multi-faceted threat encompassing data exfiltration, public exposure, and direct extortion of executives. This escalation is partly a response to improved organizational defenses against pure encryption, forcing attackers to find new leverage points. The growing engagement of corporate boards, while a positive development, is also a direct consequence of the increasing financial and reputational damages caused by these sophisticated attacks, alongside emerging governmental regulations demanding greater accountability and transparency in cyber risk management.
Key Findings
▶ Watch: Proposed solutions to deter cybercrime (3:00)
Mandia distilled his extensive observations into five primary conclusions, painting a comprehensive picture of the current cybersecurity state:
- Few Risks or Repercussions to Threat Actors: A central theme was the perceived lack of significant risk or consequence for criminal threat actors, which emboldens them to continue and even accelerate their offensive campaigns. While espionage is an acknowledged reality between nations, Mandia emphasized that the "intolerable" threshold has been crossed by criminal enterprises, causing damages ranging from $100 million to $800 million in some cases. This low-risk environment for attackers is a significant driver of the escalating threat landscape.
- Acceleration of Innovation on Offense: Mandia noted a significant acceleration in offensive innovation, particularly evidenced by an unprecedented number of zero-day exploits discovered in the wild. This innovation is not limited to sophisticated state-sponsored groups but is also permeating criminal operations, leading to more effective and evasive attack techniques across the board.
- Ransomware Has Evolved: The nature of ransomware attacks has undergone a profound transformation. Beyond merely encrypting data, ransomware operations now routinely involve data theft, extortion, and even harassment of individuals and executives. This multi-pronged approach aims to maximize pressure and financial gain, even when organizations have robust backup and recovery strategies.
- Boards More Engaged: Corporate boards are demonstrating an unprecedented level of engagement in cybersecurity matters. This increased oversight is driven by several factors, including heightened media attention to breaches, evolving regulatory requirements (such as the US government's Security and Exchange Commission reporting mandates), and a growing understanding of cyber risk as a fundamental business risk.
- Best Year for Public-Private Partnership: Despite the grim offensive landscape, Mandia highlighted a significant positive development: the strongest partnership ever between government and the private sector in cybersecurity. This collaboration is fostering initiatives like "Secure by Design" principles and leading to critical reports with actionable recommendations, such as those from the Cyber Safety Review Board (CSRB), indicating a more unified and effective defensive front.
Technical Deep Dive
▶ Watch: Sharp rise in zero-day exploits observed (4:30)
The technical core of Mandia's presentation revolved around the evolving methodologies of threat actors and the mechanisms they leverage for initial access, persistence, and impact.
A standout finding was the dramatic increase in zero-day exploits observed in the wild. In the past year, Mandiant and Google identified 97 zero days, a stark contrast to the historical average of 10 to 15 per year. Approximately one-third of these were discovered by Mandiant and Google teams. The impact was widespread, affecting 31 different vendors, a significant expansion from 2018 when only about four companies outside the "big three" (Microsoft, Google, Apple) were typically targeted. This proliferation suggests that cyber intrusions are "paying off," making the discovery and exploitation of novel vulnerabilities a highly profitable endeavor for both nation-state and criminal actors. Potential reasons for this surge include improved defensive capabilities forcing attackers to use zero days, increased funding for offensive research, the nascent role of AI in vulnerability discovery, or simply a decline in software quality.
The primary initial access method has notably shifted from spear phishing to direct exploitation since 2020. Mandia listed the top three exploited vulnerabilities in 2023, though specific CVEs were not detailed in the talk. This change underscores the critical importance of attack surface management and patch management for all organizations.
Chinese Nexus Espionage groups have shown significant improvements in their tradecraft, leading in zero-day exploitation with 12 attributed zero days in the past year, compared to only two from the next most active nation-state. These groups increasingly rely on custom code to compromise edge devices such as VPNs and email gateways. This strategy allows them to circumvent traditional endpoint detection and response (EDR) solutions, as these devices often lack EDR agents. Furthermore, Chinese and other sophisticated threat actors are increasingly employing Living Off The Land (LOTL) techniques, utilizing legitimate system tools and processes to remain stealthy and blend into normal network activity, making detection significantly harder.
Spear phishing, while no longer the leading initial access vector, has also evolved. Attackers are adapting to improved defenses like disabled macros in Microsoft Office documents, enhanced secure email gateways, and widespread multi-factor authentication (MFA). The new tactics involve using other communication channels and leveraging links that bypass email gateway inspection. Mandia highlighted three key detection strategies:
- Monitoring web proxy logs for suspicious downloads of executable files (e.g.,
.exe,.bat,.com,.vbs). - Inspecting for downloads from password-protected compressed archives, which often evade secure email gateway scrutiny.
- Setting up rules to monitor downloads from third-party storage services (e.g., OneDrive, SharePoint, Google Drive) if these are not standard for internal operations, as attackers use them to host malicious payloads. Mandiant's M-Trends report provided 12 specific rules for detecting these new spear phishing techniques.
Overcoming MFA has also become a refined art for attackers. While push notification fatigue and the compromise of one-time passwords (OTPs) are known methods, the most devastating attacks now frequently involve social engineering help desks and SIM swapping. Attackers, often bold and native English speakers, manipulate help desk personnel into providing OTPs or resetting credentials, granting them access to networks. This highlights a critical human element vulnerability that technology alone cannot fully address.
Finally, threat actors are demonstrating better OPSEC and evasion. This includes leveraging local IP addresses or IP addresses within the victim's own nation for command and control infrastructure, making attribution and detection more challenging. They are also increasingly targeting employees outside the enterprise network, compromising home networks to gain access to enterprise resources through keyloggers or stolen credentials posted on dark web forums like Telegram. Custom malware is now often designed to "append Python to other pre-existing code" on compromised edge devices, further evading detection by blending with legitimate processes. The top five TTPs (Tactics, Techniques, and Procedures) observed post-breach, requiring robust security operations for detection, include:
- Detecting anomalous use of PowerShell.
- Identifying anomalous HTTP/HTTPS traffic.
- Noticing lateral movement via RDP or remote RDP from outside the network.
- Monitoring service execution.
- Detecting file deletion (though Mandia acknowledged this remains a challenging area for effective rules).
Despite the escalating offensive innovation, Mandia presented an encouraging statistic: dwell time—the period an attacker remains undetected in a network—has significantly decreased. From 416 days in 2011, it dropped to 16 days, and further to 10 days in the past year, partly due to faster detection of ransomware. Furthermore, organizations are becoming more adept at self-detecting breaches, with self-detection rates rising from nearly 0% in 2004-2005 to 54% today, indicating a substantial improvement in internal security operations and monitoring capabilities.
Demo / Proof of Concept
▶ Watch: Exploitation replaces phishing as top attack vector (6:10)
Kevin Mandia's presentation focused on high-level observations, trends, and strategic implications derived from Mandiant's extensive investigations and intelligence gathering. As such, the talk did not include a live demonstration or a detailed proof-of-concept of any specific exploit or defensive tool. Instead, it presented an analytical overview of the "State of Cybersecurity," emphasizing data-driven conclusions rather than interactive technical showcases.
Defensive Implications
▶ Watch: Chinese espionage leads in zero-day exploitation (7:10)
The insights shared by Kevin Mandia carry significant defensive implications, urging organizations to adapt their strategies to counter the evolving threat landscape.
Firstly, the call to impose risk on criminal actors is paramount. This requires a multi-faceted approach involving law enforcement, intelligence communities, and the private sector to modernize treaties, improve attribution capabilities, and eliminate safe harbors for cyber criminals globally. Tracking cryptocurrency, often used for ransom payments, is also critical to disrupt their financial incentives.
Given the acceleration of offensive innovation, particularly in zero-day exploitation, an "assume breach" mentality is no longer optional. Organizations must focus on attack surface management, rigorous patch management, and robust segmentation. The reality is that zero days will always exist, and an insider threat is always possible, necessitating a defense-in-depth approach that anticipates successful breaches.
For ransomware preparedness, organizations must move beyond basic backups. While identifying critical assets, backing up Active Directory and configuration files, and securing backups are essential, the next step is to dry run business operations without critical systems. Boards and executives demand answers on recovery time, which can only be reliably estimated through realistic simulations. Reducing identity access creep and scope and further network segmentation remain vital to minimize blast radius.
The evolution of spear phishing and MFA bypass techniques demands a more sophisticated approach to user education and identity management. Organizations must harden their MFA implementations against social engineering attacks targeting help desks and prevent SIM swapping. This involves enhanced training for help desk personnel, robust identity verification processes, and potentially moving beyond simple push notifications to more secure forms of MFA that are resistant to phishing and social engineering.
To counter improved OPSEC and evasion by threat actors, a significant investment in security operations capabilities is required. This means having the ability to detect post-exploit TTPs, such as anomalous PowerShell usage, unusual HTTP/HTTPS traffic, RDP lateral movement (especially from outside the network), and suspicious service execution. While detecting file deletion remains challenging, continuous improvement in these areas is essential to minimize dwell time.
Finally, the increasing engagement of boards and the focus on public-private partnerships offer a unique opportunity. The Cyber Safety Review Board (CSRB) recommendations for cloud service providers and the US government underscore the need for:
- Victim notification: Cloud providers must develop methods to inform customers when they believe they have been compromised.
- Enhanced logging: Cloud services should offer comprehensive and auditable security event logs as a standard feature.
- Improved Identity and Access Management (IAM): Continuous enhancement of IAM practices is crucial.
- Transparency: Cloud providers should openly share their security practices and provide regular reports on their adherence to recommendations, enabling customers to make security-informed choices beyond just availability.
- Secure by Design principles: Software vendors must prioritize security throughout their development lifecycle, learning from incidents like SolarWinds.
These recommendations, particularly the call for annual reports on security practices from major cloud providers, represent a paradigm shift towards greater accountability and informed decision-making in the procurement and use of cloud services.
Key Takeaways
- Cybercrime is Accelerating and Profitable: Threat actors face low repercussions, fueling rapid innovation in offensive techniques, particularly zero-day exploits, making cyber intrusions a highly lucrative enterprise.
- Exploitation Dominates Initial Access: The primary method of initial compromise has shifted from spear phishing back to direct exploitation of vulnerabilities, necessitating robust patch management, attack surface management, and an "assume breach" mentality.
- Ransomware is a Multi-Faceted Extortion Game: Modern ransomware extends beyond encryption to include data theft, direct executive harassment, and sophisticated extortion tactics, demanding comprehensive incident response plans that account for these evolving pressures.
- Boards are Engaged, Driving Accountability: Regulatory mandates (e.g., SEC reporting) and increasing awareness of cyber risk have significantly elevated board-level engagement, pushing for improved governance and transparency in cybersecurity.
- Defenses are Improving, but Must Evolve: Dwell time has dramatically decreased, and organizations are better at self-detecting breaches. However, defenders must continuously adapt to new spear phishing techniques, MFA bypasses (especially social engineering help desks), and advanced OPSEC, focusing on detecting post-breach TTPs.
- Public-Private Partnership is Key to Progress: Collaborative efforts between government and the private sector, exemplified by initiatives like "Secure by Design" and the CSRB recommendations, are crucial for establishing industry best practices, improving transparency, and strengthening the collective defense posture.
About the Speaker(s)
Kevin Mandia is the CEO of Mandiant at Google Cloud. A veteran in the cybersecurity field, he began his career in 1993, witnessing decades of evolution in cyber threats and defenses. Throughout his extensive experience, Mandia has been at the forefront of responding to some of the most significant breaches globally, leading Mandiant (formerly known as Mandiant and now part of Google Cloud) to become a leading incident response and threat intelligence firm. His insights are drawn from a vast repository of real-world incident data, red team exercises, and threat intelligence analysis, positioning him as a authoritative voice on the state of global cybersecurity.