Opens in a new tab
vmblog logo 2024 wht (updated)

Tessian 2022 Predictions: 2022 Will Be the Year that Nothing Really Changes in Cybersecurity

Share: 

David Marshall | Published: December 23, 2021

 

Industry executives and experts share their predictions for 2022.  Read them in this 14th annual VMblog.com series exclusive.

2022 Will Be the Year that Nothing Really Changes in Cybersecurity

By Tim Sadler, CEO of Tessian

The past year saw a number of high-profile data breaches, ransomware attacks and advanced phishing scams. Looking ahead, will anything actually change in 2022? Or will it be a continuation of the same – and just more of it? Here are some of the cybersecurity threats and trends business leaders should be aware of as they prepare for the year ahead.

Companies will need to de-shame cybersecurity mistakes in 2022

Phishing attacks will continue to be the most common type of cyber attack in 2022, with cybercriminals targeting employees over email and collaboration platforms. Why? Because human error is the most common cause of data breaches. It just takes one distracted employee to click a malicious link or download a compromised file. But IT teams can’t prevent a breach if they don’t know about it. So in 2022, security leaders need to make employees part of the solution. Instead of punishing or shaming employees when they report mistakes or vulnerabilities, IT teams must encourage it and even reward those who come forward.

More major corporate breaches will start with a text

More major ransomware attacks or high-profile corporate data breaches will start with an attacker engaging with an employee over text or chat, as social engineering attacks continue to spread beyond the corporate inbox to messaging apps and SMS. Malicious actors can reach employees on social media platforms, messaging apps like WhatsApp, or through SMS as a gateway to corporate accounts and data. Unlike corporate email and chat accounts, these personal platforms aren’t protected by an internal security team or security tooling. Meanwhile, social and messaging platforms are not doing enough to address security concerns and provide safe user experiences. The result will be a continued uptick in phishing attacks across personal messaging platforms, which will be harder to spot than the traditional email scam.

The perceived talent shortage will worsen until we rethink hiring and retention altogether

Another major challenge in 2022 will be filling the more than 500,000 open security positions in the U.S. alone. The problem is not a lack of latent or a skills gap, though; rather, it is outdated thinking around who and how we hire. The industry must take a hard look at a decades-long history of bad job descriptions and unreasonable requirements that keep talented, diverse individuals from entering the field, and rewrite the rules. As we head into 2022, the labor market has never been more challenging amid widespread staffing shortages and The Great Resignation. Hiring and retaining security talent will be a major hurdle. The security industry will need to prioritize fundamental skill sets over years of experience, rely less on automated recruiting platforms that block qualified candidates who have less traditional backgrounds, and develop strategies that enable employees to grow internally instead of being forced to look elsewhere.

Data will be attackers’ main weapon as phishing attacks increase

Widespread breaches and data leakage due to misconfigured databases and APIs have created a treasure trove of data sold on dark web communities that attackers can use to further advance their phishing campaigns in 2022. This rich dataset of personal information about specific targets – such as job title, date of birth and location – will make social engineering attacks even more convincing.

Continuously educating employees on how to spot phishing attacks and creating an easy process to report potential scams will be critical in 2022.

Year on year, the same security predictions are shared – and this will continue if security teams continually address the symptoms of vulnerabilities, rather than the causes. For example, ransomware has risen over the past few years but it is only a symptom masking underlying causes, given that the majority of ransomware attacks are caused by social engineering attacks, phishing emails and malware risks. Only by focusing on the causes – and protecting against these threats – can organizations stay secure.

##
 
ABOUT THE AUTHOR
 
Tim Sadler 
 
Tim Sadler is the Chief Executive Officer and co-founder of human layer security company Tessian. After a career in investment banking, Tim and his co-founders started Tessian in 2013, creating a human layer security solution that uses machine learning to protect people from risks on email like data exfiltration, accidental data loss and phishing.