COVID-19 and Cybersecurity: A Special Edition Review

Impact of COVID-19 on Cybersecurity

  • Rapid shift to telework multiplied cyber attack surfaces and complexity.

  • IT departments focused on securing employees' home systems, networks, and ISPs.

  • Teleconference providers (e.g., Zoom) and Virtual Private Networks (VPNs) experienced massive growth.

  • Scammers employed Information Operations (IO) principles, using emotional narratives for fraud.

  • Work and home life boundaries blurred significantly due to increased telework expectations.

  • E-commerce boomed, contributing to the decline of many brick-and-mortar stores.

  • Pandemic politicization was exploited by hostile actors to sow further dissent.

Future Cybersecurity Challenges in a Pandemic Environment

  • Anticipated annual pandemic response cycles will increase cybersecurity's importance.

  • A "whole-of-society" approach, including public and private sectors, is essential.

  • Need for clearly communicated and enforceable rules of behavior against cyber threats.

  • Future asymmetrical hybrid attacks are possible in pandemic environments.

  • Emphasis on cyber hygiene, best practices, and building resilience.

  • Paradigm shift from "Great Power Competition" to "Great Systems Conflict," requiring cyber resilience domestically and with allies.

  • Information warfare (e.g., China's strategic narrative leveraging the pandemic) is a key concern.

  • Increased focus on medical device cybersecurity risks and vulnerabilities.

  • Analysis of factors determining which states are most likely to initiate cyberattacks.

The COVID-19 pandemic significantly increased cyber attack surfaces due to widespread telework, forcing IT departments to secure diverse home environments. This led to a boom in teleconference and VPN services and saw scammers exploit emotional narratives through information operations (IO). The lines between work and home blurred, e-commerce surged, and hostile actors capitalized on pandemic politicization to sow dissent. Looking ahead, annual pandemic cycles will heighten cybersecurity's importance, necessitating a "whole-of-society" approach with clear rules against cyber threats. Future challenges include asymmetrical hybrid attacks, a need for robust cyber hygiene and resilience, a shift to "Great Systems Conflict," and heightened concerns about information warfare and medical device cybersecurity vulnerabilities. Analysis is also needed to predict which states might initiate cyberattacks.

Dumbed down:

The COVID-19 pandemic caused more opportunities for cyberattacks because many people started working from home. This meant IT teams had to protect many different home computers and networks. Because of this, video calling services (like Zoom) and secure network connections (VPNs) became very popular. Work and home life became less distinct, online shopping greatly increased, and enemies took advantage of political arguments about the pandemic to cause problems. Looking ahead, since pandemics might happen often, staying safe online will be even more crucial. Everyone, including governments and businesses, needs to work together under clear rules to fight online threats. Future problems include tricky, mixed-method attacks, the need for good online safety habits and the ability to recover from attacks, a change towards bigger global conflicts focusing on entire systems and worries about using information to fight wars and the security of medical devices. We also need to figure out which countries are most likely to start online attacks.