CHS Networks

What can we expect to see on the horizon for cyber security trends in 2022? Four experts at IBM X-Force provided their cyber security predictions, here we review the top 9.

In the last couple of years, there’s been a shift to digital and cloud services and in how consumers and businesses accomplish tasks. With the increase in digital data, and the rise in remote working, the challenges business face have been changing too, and none more so than the threats posed by cyber criminals. Cybersecurity attacks increase year on year, and 2022 is expected to see ever greater growth, especially with Russia’s invasion of the Ukraine, where it’s expected the war will be fought on the ground and in cyberspace.

Nick Rossmann, the former Global Threat Intelligence Lead at IBM X-Force, predicts:

Ransomware Attacks That Spiral Into Extortion Ransomware

Nick Rossamann suggests that in the upcoming months we’ll start seeing a rise in ‘triple extortion ransomware’ as cyber criminals try to increase their revenue with a relentless barrage of attacks. An extortion attack is where a ransomware attack launched on one business develops into an extortion threat for its business partners. These attacks target not only the intended victim, but once data has been compromised, the attackers then target the victim’s business partners. Any data compromised in the initial attack that can be used to leverage a client, partner, supplier, will be used to extort a further attack on additional victims.

Supply Chain Attacks That Cripple Many Businesses

COVID-19 restrictions highlighted the vulnerabilities of the supply-chain model. -A supply chain bottleneck or break can cripple an entire network of businesses and their revenue. In 2022, it’s expected that there’ll be an increase of cyber criminals releasing targeted attacks in the supply chain for both consumer and enterprise level businesses. With so many business links in a supply chain, there are many potential weak spots for incomplete or ineffective cyber security. It’s expected that cyber criminals will hunt, discover, and target the weakest links within a chain in order to demand ransom from all businesses.

AI to Change Passwords as We Know Them

The emergence of more and more cyberattacks, combined with the increased uptake of online accounts, ensures further weakness in cyber security practices. It’s well known that many users and companies still allow poor password practices, which are the main cause of cyber breaches. Once compromised, a password often leads an attacker to discovering more passwords that can also be leveraged for cybercrime. One exposed password provides endless potential for continuous attacks.

With most systems requiring authentication before access or use, users are faced with the task of remembering or managing many passwords. Those still not using password managers will struggle, and the common practice of using slight alternatives of a password i.e. LetMeIn1, LetMeIn2, LetMeIn3! – is a highly unsafe practice. AI (Artificial Intelligence) and biometric technologies are enabling consumers to rely on alternative forms of authentication to access their accounts.  These password alternatives include face ID, fingerprints and other forms of biomentric authentication. With 2FA authentication becoming easier to implement and manage, adoption should grow, making systems safer.

Security Benefits of The Hybrid Cloud to Be Better Utilised

As businesses have moved to cloud services, so have hackers, meaning cyber-attacks on cloud environments are increasing. There’s been a rise in Linux-based malware and container targeting, and in response, businesses are choosing to minimise their risk by using multiple environments to house their data. The hybrid-cloud environment allows better data management and protection, and critical data can be further secured with higher security practices.

Charles Henderson, Head of IBM X-Force predicts:

Businesses to Invest More Heavily in Their Cyber Security Due to Tighter Regulation

The requirement for governments to provide security mandates to businesses means that over the next few years, more resources will be allocated to security. Driven by the fear of regulatory fines and crippling business consequences if mandatory security requirements aren’t met, security budgets for most companies will increase.

Regional Regulatory Solutions to Lead to Global Business Problems

Businesses around the world will increase their spending to meet various cybersecurity regulations to navigate conflicting government expectations. Businesses and organisations will further struggle to ensure their compliance, and at the same time, mandates will most likely be ineffective.

While security mandates are an important step in creating a standard cyber resilience baseline, the differing regional regulations, will lead to global business challenges to adherence due to conflicting security requirements. This struggle will lead to further user access audits, and additional data access conditions.

Cyber Security to Be Further Defined in Line with Zero Tolerance

Zero tolerance for cyber security measures will become more commonplace for businesses. As to obtain customer trust, businesses must be able to prove their security strategy and compliance. It’s expected that government and private industry will place additional measures on their partner relationships, reassessing all access to their data and undertaking more user and application access audits.

Laurance-Dine, Lobal Partner, IBM X-Force Incident Response predicts:

Ransomware Syndicate Takedowns to Shift Attackers’ Target Focus

Throughout 2022 cyber-criminal groups will seek easier victims and are expected to target more vulnerable territories. We expect their attacks to target those without security resources, defences, or an imposed government cyber strategy. This shift in focus will no doubt mean that other, more lucrative nations, including the UK and US, will most likely witness a decrease in cybercrime. This change in victim choice is driven by successful cybercriminal capture, where effective notable ransomware criminals have been unmasked, and been brought to justice.

Limor Kessem, Executive Security Advisor, IBM Security, predicts:

Direct Denial of Service + Encryption + Data Hostage = Extortion

Governments are introducing cryptocurrency modifications, working to limit payments to ransomware gangs, and permitting changes to crypto currency to impede its use. This could mean that compromised companies may find themselves unable to pay a ransom, leaving cyber criminals to employ pressure tactics to extort businesses. It’s therefor crucial that businesses invest in their backup and disaster recovery solutions.

It’s clear that the move to remote and hybrid working practices has provided cyber criminals with more vulnerabilities to leverage. If you’ve addressed your remote working practices but not your cyber security solutions to protect your new environment, your business is potentially at risk of greater threat than ever.

With effective cyber security solutions and experts on hand to curate, implement and manage a cyber security strategy for the ever-changing cyber landscape, your business will be better protected. You’ll be in a much better position to recover should you be a victim of a cyber attack.

Talk to one of our cybersecurity experts to discover which security solutions best fit your business

Get in Touch