Opens in a new tab
vmblog logo 2024 wht (updated)

PDI Security Solutions 2022 Predictions: The Year of Security Awareness

Share: 

David Marshall | Published: December 23, 2021

 

Industry executives and experts share their predictions for 2022.  Read them in this 14th annual VMblog.com series exclusive.

2022: The Year of Security Awareness

By Chris Berry, CTO, PDI

For most companies, it’s not a matter of if their IT systems and operations will be attacked next year, but rather a matter of when. That’s why it’s so critical to be forward-thinking, proactive, and prepared when a cyberattack does happen. Here are five cybersecurity trends that businesses can expect to see in 2022.

1.)   Ransomware: Ransomware will continue to be a major threat, especially for small to medium-sized businesses (SMBs). Bad actors and cybercriminals are getting much more aggressive, and they’re using more sophisticated tools developed by nation-states. Unless a business has a 24/7/365 monitoring solution, they’re going to be vulnerable.

2.)   Extortionware: Similar to ransomware, extortionware poses a major threat. In addition to the attackers saying “Hey, I’ve got your data,” they also threaten to release that data. This becomes a significant issue if sensitive information gets exposed to the public. When extortionware attacks happen, the blast radius also becomes much broader, because the exposed information can include business partners, vendors, and customers. As a result, there’s much more pressure on businesses to comply with the original ransom demands.

3.)   Security Awareness: Security awareness training will become an increasingly vital aspect of cybersecurity because the human element is still the highest risk factor in data breaches. Businesses need to prioritize security training with more varied and frequent engagements with employees to reinforce security message that employees are often the key to preventing a breach.

4.)   IT Staff Education: Many IT teams have been playing catch-up when it comes to security, and they’re still behind on adequately protecting their organizations. When the pandemic pushed most companies into a work-from-home model, IT teams had to scramble to transition their organizations as quickly as possible. Because of this immediate shift in focus, IT likely had to take some shortcuts in terms of security. Next year will be vital to re-evaluating security best practices, not just from a business perspective but for the entire industry.

5.)   Outsourcing Security: SMBs should prioritize preparing for security breaches. Unfortunately, most SMB organizations don’t have the in-house IT staff, skills, or expertise to create a viable security strategy for today’s threat landscape. Organizations have either lost employees due to the Great Resignation or have “soft resources” on staff, where security isn’t their core expertise. In these situations, businesses should look into working with a third-party partner to fill in any cybersecurity skills gaps as part of implementing a robust security plan. 

With cyberthreats continuing to escalate in both number and scope, security is definitely one of the top areas for IT teams to focus in 2022. They need to thoroughly understand the threat landscape and where they stand in terms of threat prevention, detection, and response. If they’re able to follow best practices on their own, that’s great. But, if they need to supplement their internal efforts, there are numerous managed security services and vendors with which to partner.

As always, time is critical to identifying and responding to potential threats. By the time a breach is detected, the damage might already be done. Thus, the best approach is to double down on prevention, because it’s no longer a matter of if, but when, they’ll experience a cyberattack.

##

ABOUT THE AUTHOR

Chris Berry, Chief Technology Officer & General Manager, PDI Security Solutions

Chris Berry 

Chris Berry joined PDI in 2017 as CTO. She’s had a significant impact on the business, including spearheading many initiatives, modernizing PDI’s internal infrastructure and processes, accelerating PDI’s cloud-based solutions, and unifying the global development team. In addition to her role as CTO, she oversees the PDI Security Solutions line of business, extending the company’s capabilities in cloud security. Chris has over 30 years of experience and is passionate about exploring the art-of-the-possible and fostering a culture of innovation. Prior to joining PDI, Chris was CTO for PeopleAdmin and SVP of Engineering at Accruent. Chris started her technology career in the United States Air Force in 1991 as a software developer.