---
title: US firms and the growing risk of cyberespionage
description: Governments, especially in the US, are trying to put a stop to cyberespionage by creating agreements to promote cyber awareness and prevent cyber threats.
image: http://www.cloudmask.com/hubfs/cyber_espionage1.jpg
---

[![CloudMask - Data protection under breach](https://www.cloudmask.com/hs-fs/hubfs/Horizontal-larger-text.png?width=223&height=40&name=Horizontal-larger-text.png "CloudMask - Data protection under breach")](https://www.cloudmask.com)

- [For Business](https://www.cloudmask.com/business)
- [For Enterprise](https://www.cloudmask.com/enterprise)
- [For Developers](https://www.cloudmask.com/saas-developers)
- Resources 
    - [Blog](https://www.cloudmask.com/blog)
    - [Videos](https://www.cloudmask.com/videos)
    - [Help](http://help.cloudmask.com)

# US firms and the growing risk of cyberespionage

<https://www.cloudmask.com/blog/data-privacy-overseas-germany-to-investigate-u.s.-businesses> <https://www.cloudmask.com/blog/data-privacy-disaster-safe-harbor-agreement-struck-down>

![cyber_espionage1.jpg](http://www.cloudmask.com/hs-fs/hubfs/cyber_espionage1.jpg?width=294&height=174&name=cyber_espionage1.jpg "cyber_espionage1.jpg")

Cyberspace has no boundaries or borders, and this spells trouble for corporations around the world.

Cyberspace has no boundaries or borders, and this spells trouble for corporations around the world. In an attempt to stamp out cyberespionage, governments are creating agreements dedicated to preventing cybercriminal activity and promoting better cyberawareness on both a federal level and a citizen one.

In a recent meeting between U.S. President Barack Obama and President of China Xi Jinping, the pair of officials negotiated a deal ensuring that neither government [will "knowingly support cyber-enabled theft of intellectual property,"](https://www.whitehouse.gov/the-press-office/2015/09/25/fact-sheet-president-xi-jinpings-state-visit-united-states) a category that includes confidential business information, trade secrets and consumer data that provides enterprises with unique advantages.

 

*"Foreign cyberthreats are after trade secrets and sensitive data."*

However, despite mutual agreements, stopping cyberespionage and preventing the digital theft of intellectual property is proving to be very difficult - for both federal governments and corporations. In a CrowdStrike blog post, co-founder of the company, Dmitri Alperovitch, wrote on October 19, 2015 that in the past three weeks, there have been "a number" of cyberattacks [launched on American companies](http://blog.crowdstrike.com/the-latest-on-chinese-affiliated-intrusions-into-commercial-companies/). In this case, pharmaceutical firms and technology manufacturers were primary targets, but of course, foreign cyberthreats target trade secrets and sensitive data regardless of which business owns it.

**Threats from everywhere**  
Alperovitch indicated that Deep Panda - an organized China-based hacker organization - was responsible for some of the recent attacks on U.S.-based companies, but there are more cybercriminal groups than that, and many of them exist outside of China. NBC News reported that [North Korea, Russia, Syria and Iran](http://www.nbcnewyork.com/news/national-international/Threat-Foreign-Hackers-Grows-US-Companies-Slow-to-React-334965431.html) are also countries that potentially harbor organized hacker organizations, as they've been linked to attacks in the past.

In addition, anyone with hacking know-how and enough money to purchase exploits from the Darknet poses as a threat to American institutes in all industries. The Sony incident, the Target breach and the frequent infiltration of small business networks prove that cybercriminals are after anything they can grab, and intellectual property theft is just a bonus.

**Why American companies?**  
There are a few specific reasons why foreign cyberthreats are more dangerous than those on American soil.

For one, there aren't hard-and-fast laws that could leveraged against hackers and cybercriminal groups in different countries, especially when their governments are not as close to the U.S.'s as they could be. Whether supported by federal agencies or rogue, it doesn't matter, as there is no way to prosecute a foreign hacker for breaching the networks and stealing data from American corporations.

"If you hack in the United States, if it's a U.S. company, you do get caught and [there's penalties for that](http://techcrunch.com/2015/10/22/ventured-cyber-hacking-is-the-new-global-battlefield/)," Kevin Mandia of Mandiant told TechCrunch contributor Randy Komisar. "But if you act from North Korea, China, Russia, Iran, \[they\] just keep doing it."

![Hackers, especially those from different countries, are likely to keep launching cyberattacks until they succeed.](http://pictures.brafton.com/x_0_0_0_14082810_800.jpg)Hackers, especially those from different countries, are likely to keep launching cyberattacks until they succeed.

Secondly, Mandia asserted that cyberwarfare is very different in that it's "asymmetrical." In other words, one hacker could take down a major corporation, even if the business has the biggest cybersecurity team. Cybercriminals will keep trying to breach firewalls and phish for credentials, and the consequences for failing aren't severe. Sooner or later, after banging on the door for months, a vulnerability will appear and hackers will exploit it.

Lastly, businesses aren't prepared to prevent today's cyberthreats from wreaking havoc on corporate networks and inside enterprise data centers.

"The world has really changed," Larry Ponemon, the Institute's founder, told NBC News. "Companies are doing a good job - but attackers, and not just nation-states, but all attackers, [they're becoming more sophisticated](http://www.nbcnewyork.com/news/national-international/Threat-Foreign-Hackers-Grows-US-Companies-Slow-to-React-334965431.html), strategic and just nastier. The gap is growing."

**The CloudMask Solution**  
If data breaches are inevitable - and they certainly are - businesses must focus on protecting their most sensitive assets, which is typically consumer data and intellectual property or trade secrets. Cybercriminals from around the world have plenty of time and different sophisticated methods for finding their way onto corporate networks, and therefore, the best solution is to encrypt data and hold onto the key.

CloudMask is a Data-centric protection solution that can prevent data theft even when networks are breached, as users have the ability to obscure data with encryption and they will be the only person who can unlock that information and its true value.

![Protection Under Breach](https://www.cloudmask.com/hubfs/GIF_Animation/Gif%20Animation%20All.gif)

*With CloudMask, only your authorized parties can decrypt and see your data. Not hackers with your valid password, Not Cloud Providers, Not Government Agencies, and Not even CloudMask can see your protected data. *[Twenty-six government cybersecurity ](https://www.commoncriteriaportal.org/)*agencies around the world* [back these claims.](https://www.cloudmask.com/hubfs/CloudMask_Aug2016/pdf/Common_Criteria_Cert.pdf?t=1486380970425)

[![TRY IT NOW](https://no-cache.hubspot.com/cta/default/468512/82253abc-9465-4974-b5ea-2a46f934181b.png)](https://cta-redirect.hubspot.com/cta/redirect/468512/82253abc-9465-4974-b5ea-2a46f934181b)

Watch our video and demo at [www.vimeo.com/cloudmask](http://www.vimeo.com/cloudmask)

Share this article:

- [Tweet](https://twitter.com/share)

### Related posts

[![How to evaluate and select the best encryption services](https://www.cloudmask.com/hubfs/Lock_01.jpg)](https://www.cloudmask.com/blog/how-to-evaluate-and-select-the-best-encryption-services)

[How to evaluate and select the best encryption services](https://www.cloudmask.com/blog/how-to-evaluate-and-select-the-best-encryption-services) March 12, 2018

[![The Myth of “Staying One Step Ahead of the Hackers”](https://www.cloudmask.com/hubfs/Hacker%20one%20step.png)](https://www.cloudmask.com/blog/the-myth-of-staying-one-step-ahead-of-the-hackers)

[The Myth of “Staying One Step Ahead of the Hackers”](https://www.cloudmask.com/blog/the-myth-of-staying-one-step-ahead-of-the-hackers) March 08, 2018

[![Why Defense In Depth Is Not Good Enough](https://www.cloudmask.com/hubfs/defense%20in%20depth.jpg)](https://www.cloudmask.com/blog/why-defense-in-depth-is-not-good-enough)

[Why Defense In Depth Is Not Good Enough](https://www.cloudmask.com/blog/why-defense-in-depth-is-not-good-enough) March 02, 2018

[![Why the government isn't a fan of commercial encryption](https://www.cloudmask.com/hubfs/brafton_images/The-government-want-the-ability-to-conduct-surveillance--on-encrypted-communications_2135_40071057_0_14090523_500.jpg)](https://www.cloudmask.com/blog/why-the-government-isnt-a-fan-of-commercial-encryption)

[Why the government isn't a fan of commercial encryption](https://www.cloudmask.com/blog/why-the-government-isnt-a-fan-of-commercial-encryption) November 16, 2017

[![The Encryption That Businesses Need, But CISOs Forget About](https://www.cloudmask.com/hubfs/Key%20-%202%20heads%20Depositphotos_24641695_original.jpg)](https://www.cloudmask.com/blog/the-encryption-that-businesses-need-but-cisos-forget-about)

[The Encryption That Businesses Need, But CISOs Forget About](https://www.cloudmask.com/blog/the-encryption-that-businesses-need-but-cisos-forget-about) September 19, 2017

[![Why Your Data Security Strategy Should Include Data Masking](https://www.cloudmask.com/hs-fs/hub/468512/file-2584554648.jpg)](https://www.cloudmask.com/blog/why-your-data-security-strategy-should-include-data-masking)

[Why Your Data Security Strategy Should Include Data Masking](https://www.cloudmask.com/blog/why-your-data-security-strategy-should-include-data-masking) September 19, 2017

Please enable JavaScript to view the &lt;a href="http://disqus.com/?ref\_noscript"&gt;comments powered by Disqus.&lt;/a&gt;

### Sign Up for our Newsletter to get the latest in everything cyber security. We care about your privacy, let us show you how.

### Recent Posts

### Posts by Topic

- [Breach (29)](https://www.cloudmask.com/blog/topic/breach)
- [Certifcation (3)](https://www.cloudmask.com/blog/topic/certifcation)
- [cloud computing (7)](https://www.cloudmask.com/blog/topic/cloud-computing)
- [Cloud threats (6)](https://www.cloudmask.com/blog/topic/cloud-threats)
- [Common Criteria (2)](https://www.cloudmask.com/blog/topic/common-criteria)
- [Compliance (18)](https://www.cloudmask.com/blog/topic/compliance)
- [costs (1)](https://www.cloudmask.com/blog/topic/costs)
- [cyber threats (22)](https://www.cloudmask.com/blog/topic/cyber-threats)
- [Cybercrime (6)](https://www.cloudmask.com/blog/topic/cybercrime)
- [data centric protection (1)](https://www.cloudmask.com/blog/topic/data-centric-protection)
- [Data Masking (25)](https://www.cloudmask.com/blog/topic/data-masking)
- [data privacy (28)](https://www.cloudmask.com/blog/topic/data-privacy)
- [data residency (4)](https://www.cloudmask.com/blog/topic/data-residency)
- [data security (9)](https://www.cloudmask.com/blog/topic/data-security)
- [Data Sovereignty (8)](https://www.cloudmask.com/blog/topic/data-sovereignty)
- [defense in depth (1)](https://www.cloudmask.com/blog/topic/defense-in-depth)
- [Email Security (5)](https://www.cloudmask.com/blog/topic/email-security)
- [encryption (8)](https://www.cloudmask.com/blog/topic/encryption)
- [financial (1)](https://www.cloudmask.com/blog/topic/financial)
- [Google (5)](https://www.cloudmask.com/blog/topic/google)
- [governance (3)](https://www.cloudmask.com/blog/topic/governance)
- [Government surveillance (13)](https://www.cloudmask.com/blog/topic/government-surveillance)
- [hacking (1)](https://www.cloudmask.com/blog/topic/hacking)
- [Healthcare (2)](https://www.cloudmask.com/blog/topic/healthcare)
- [insider threats (3)](https://www.cloudmask.com/blog/topic/insider-threats)
- [Legal (6)](https://www.cloudmask.com/blog/topic/legal)
- [New Security Paradigm (6)](https://www.cloudmask.com/blog/topic/new-security-paradigm)
- [Password (4)](https://www.cloudmask.com/blog/topic/password)
- [Personal Data Protection (17)](https://www.cloudmask.com/blog/topic/personal-data-protection)
- [PKI (1)](https://www.cloudmask.com/blog/topic/pki)
- [Regulation (1)](https://www.cloudmask.com/blog/topic/regulation)
- [RSA2017 (1)](https://www.cloudmask.com/blog/topic/rsa2017)
- [Shadow it (1)](https://www.cloudmask.com/blog/topic/shadow-it)
- [Tokenization (3)](https://www.cloudmask.com/blog/topic/tokenization)
- [User Privacy (10)](https://www.cloudmask.com/blog/topic/user-privacy)

see all

- [About Us](https://www.cloudmask.com/about)
- [Pricing & Plans](https://www.cloudmask.com/subscription-plans/)
- [Partners](https://www.cloudmask.com/about/cloud-partners/)
- [Get in touch with us](https://www.cloudmask.com/contact-us)

**CloudMask Inc.**  
+[1 (819) 282-1501](tel:1%20(819)%20282-1501)[+1 (866) 202-4443](tel:1-866-202-4443)

- What We Protect 
    - [For Business Users](https://www.cloudmask.com/business)
    - [For Enterprise](https://www.cloudmask.com/enterprise)
    - [For Developers](https://www.cloudmask.com/saas-developers)
- Who We Help 
    - [Legal](https://www.cloudmask.com/e2ee-for-legal-sector)
    - [Financial](https://www.cloudmask.com/e2ee-for-financial)
    - [Healthcare](https://www.cloudmask.com/e2ee-for-healthcare)
    - [Education](https://www.cloudmask.com/e2ee-for-education)
- Resources 
    - [Help & Support](http://help.cloudmask.com)
    - [Blogs](https://www.cloudmask.com/blog)
    - [News](https://www.cloudmask.com/news)
    - [Videos](https://www.cloudmask.com/videos)

[![Cloudmask](https://www.cloudmask.com/hs-fs/hubfs/CloudMask_Aug2016/CM-Logo-200-50.png?width=200&height=50&name=CM-Logo-200-50.png "Cloudmask")](https://www.cloudmask.com/)

© 2012-2017 CloudMask All Rights Reserved