Debasish Mukherjee, Vice President, APJ, SonicWall

1. Identity-based attacks

“Identity is the new perimeter,” said Debasish. “Legacy perimeter security no longer protects everything.” Stolen credentials, weak identities, and identity fraud are driving breaches.

To counter this, SonicWall has embedded a credential auditor into its OS. The tool will tell a user, for example, when he or she is inputting a password that this ID or this password is already compromised, and it will keep telling the user till the best credential protection is reached.

2. Legacy vulnerabilities and unpatched systems

Users still running legacy VPNs and expired firewalls are leaving open doors as entry points for cybercriminals.

Debasish noted that price-sensitive markets in APJ often keep obsolete gear “because it still works,” without realizing the exposure. Meanwhile, long-running issues like Log4j remain: “Log4j is still a very popular attack surface… using breached information and finding out that patch management is not done.”

Add to this the distributed enterprise — remote work, SaaS, cloud workloads, OT and IoT — and the traditional perimeter effectively disappears: “Because now there is no perimeter and we have also started using a lot of IoT devices everywhere, all these are creating a problem.”

  • Healthcare

    “They cannot afford a downtime; even a few minutes can mean people will die,” Debasish said bluntly.

    Attackers understand that life-and-death operations and heavy reliance on connected equipment make hospitals highly likely to pay. SonicWall has observed 13 million remote exploitation attempts in healthcare alone.

  • Financial services

    “Where there is money… there is value.” And reputation risk makes financial services a prime ransomware target.

    Debasish added: “If a bank gets breached, its customers will go to another bank… so there is a high chance these organizations will pay.”

  • Manufacturing

    Manufacturing’s transition from OT-heavy legacy environments to IT/OT convergence is creating a gap. Attackers exploit OT as an easier entry point to get into IT.

    Any prolonged downtime directly impacts revenue: “Any manufacturing unit, if it is down for five–six hours, will lose a lot of money, and out of panic they will pay the ransom.”