CHS Networks

In 2022, cybersecurity simply HAS to be top of the agenda for all businesses, no matter their size or industry. Ransomware and cyberattacks are rising dramatically. The Gov.uk Cyber Security Breaches Survey 2021, published in March 2021 confirmed that four in ten businesses (39%) and a quarter of charities (26%) had reported having cyber security breaches or attacks in the last 12 months. Like previous years, this number was higher among medium businesses (65%), large businesses (64%) and high-income charities (51%). It’s no wonder that finally, business owners are seeing the need to invest in effective cyber security solutions.

In January 2022, the National Cyber Security Centre confirmed that the Log4j vulnerability is still allowing cyber criminals to use vulnerabilities in outdated software to target organisations. The criminals are apparently using an MS Office vulnerability that is over a decade old!

This dramatic increase in threats and successful breaches has ensured that businesses are finally aware that no matter their size or industry, they are at risk of being target of cybercrime. Andre Durand, the CEO and founder of Ping Identity has provided some compelling predictions to the cyber landscape for 2022 and beyond, which we look at in this article.

The 4th Environmental, Social and Corporate Governance Score – ESG will be Cybercrime

This year, it’s suspected that cybersecurity will become the fourth socially conscious responsibility standard for the Environmental, Social and Corporate Governance score. ESG is an evaluation of data concerning a firm’s collective conscientiousness for social and environmental factors. This potential latest requirement has been influenced not only by the growth of cyber-crime, but in reaction to the changes in working practices, and the move to more digital working solutions defined by the pandemic. With more remote workers, there are far more opportunities for cyber criminals to successfully attack a business.

Multi-Factor- Authentication will Become Mandatory

It’s expected that in response to the increased threats, one of the simplest cyber security measures – Multi-Factor Authentication (MFA), will shortly become a world-wide directive. It’s already commonplace for many sectors including banking, education, utilities, healthcare, and government, and during 2022 its expected that many other industries and verticals will follow suit. Those businesses with lesser security could potentially find themselves losing customers and clients if they’re not seen to be implementing strong security measures. Such is the global growing concern for cyber security, if a business isn’t demonstrating their dedication to data and cyber security, it’s highly likely that a prospect and even a client, will move to a competitor that is.

Malevolent Automated Attacks from Internet Robots – Bots, will Increase

Bots are commonplace and malevolent bots are already causing havoc. It’s suspected that there will be a huge increase in automated attacks from bots mimicking real people; the threats to customer facing systems are high. Bots can deliver automated attacks, taking over accounts, actioning fraudulent transactions and credential stuffing assaults. Shoe bots are also a threat: these sophisticated software components can automatically and quickly buy limited availability stock to then sell on at a grossly inflated price.

There is swiftly becoming no real way to differentiate a bot from an authentic ‘human’ transaction; bots are fully capable of mimicking human activity, from typing speeds and errors, to the pressure applied to a touch screen device. All these implementations are there to convince systems that they are indeed not a bot, but a real-human. Zero Trust authorisation is now more important than ever.

Official ID Documentation will go Digital

Digital wallets will become the norm, all mobile devices could provide not just digital wallets, as many of us are using already, but digital IDs too. These will help reduce fraud and identity theft, and minimise the need for physical ID. But with your ID on a mobile device, it can easy be stolen or lost, batteries can run low, and Wi-Fi or cellular coverage may be compromised, meaning that the user is unable to access their identity on their device.

Increase in Attacks on Zombie and Shadow Application Programming Interfaces – APIs

A shadow API is one that lives outside the normal IT governance management and security processes. Often undocumented, they create massive security and governance risks for organisations due to the lack of visibility into how data and applications may be accessed by third parties. Zombie APIs are aptly named as they’re APIs that are assumed to be disabled, but are still active, hidden within applications. They have the potential to lead to account take overs and fraudulent transactions. Durand suggests that more than 90% of attacks in 2022 will focus on APIs.

Information Technology and Operational Technology will Converge

The security of operational physical devices and information technology will merge as IT teams assume responsibility for both. IT and OT will become the same operation, joining technology solutions together. Solutions will need to be able to define physical access and virtual access to systems. For example, key cards to access offices and to get through physical security, and access codes or passwords to access apps and programmes in the cloud, on tablets, phones or computers. Universal security requirements will need to be implemented for all those who are part of the process.

More than Security – UE will be Prioritised

Alongside security issues, considerations for use will need to be addressed and improved. Users and customers are increasingly looking for seamless digital experiences, access and activity must be unified and to some extent, enjoyable. Consumer-facing companies that don’t offer a smooth user experience on their platforms, accounts, or website will be discarded for companies that do.

Demand for Chief Information Security Officers will surge

According to a Gartner forecast, “more boards will set up a dedicated cybersecurity committee by 2025”, and as the focus on cybersecurity increases, by 2025 the CISO along with the company board, will set up a dedicated cybersecurity committee.

Durand commented “CISOs can clearly define tangible risks to the business and present solutions to reduce or completely remove risks to the business that could cause monetary or brand reputation issues”. He also confirmed, “The office of the CISO helps to educate and keep employees fluent and aware of security risks to the business and to themselves. Having the CISO at the right level inside of the company can ensure high and critical security risks are being addressed in a timely manner.”

If you’d like to learn more about how the cyber landscape changes could impact your business, or you’d like to understand how you could better protect your data, clients and company – get in touch. The Cyber Security experts at CHS Networks, are happy to discuss your needs, fears, concerns and future requirements, and help to implement a plan for prevention, incident response and cyber security.

Get in touch