Opens in a new tab
vmblog logo 2024 wht (updated)

Splunk 2022 Predictions: Ransomware supply chain hacks to get worse and threat intelligence sharing to increase

Share: 

David Marshall | Published: January 17, 2022

 

Industry executives and experts share their predictions for 2022.  Read them in this 14th annual VMblog.com series exclusive.

Ransomware supply chain hacks to get worse and threat intelligence sharing to increase

By Ryan Kovar, Distinguished Security Strategist and Leader of SURGe, Splunk

In the last year, we’ve had the sudden spike in major supply chain and ransomware attacks on the heels of the COVID-19 pandemic, whose disruptions included a sudden shift to remote work. Despite all this, the security industry has a pretty good track record. The perimeter shifted, but the gates held.

The security challenge can feel like an endless roller coaster, but understanding the threats at each level can help organizations take control, deflecting attacks, spotting intrusions and integrating predictive measures. 

We can’t hide from threats. They’re coming (really they’re already here) and we need to evolve to stay ahead of them. Here are five trends we can expect in 2022 and what we need to prepare for, also detailed in the Splunk Data Security 2022 Predictions report:

Ransomware will increase as cybercriminals professionalize – and leverage the supply chain

As bad as the prominent ransomware and supply chain attacks of the past couple of years have been, they’ll be worse together. But it’s an inevitable combination. Ransomware is the why (money), and supply chain is the how (through third-party software that can get attackers into thousands of victim organizations at once, and more easily).

Holding an organization’s data or infrastructure for ransom is the quickest way to turn an intrusion into cold, virtual cryptocurrency, and because that’s where the money is, it’s where the adversaries are flocking.

A major public cloud service provider could be the next big breach

Both sides of a cloud service provider (CSP) partnership are vulnerable to human activity, whether it be insider attacks or a customer who misconfigures security on their side. Thing is, it’s not a matter of if, but when. We need to assume that these really unfortunate big events will happen.

Sharing of threat data will increase –  first via security vendors, later through government programs (maybe)

Not only must the sharing of threat data increase, there also needs to be better automation and integration, given the increase in noise. More threat data with better automation will allow security teams to focus their resources and investments in the most needed areas, and help overburdened analysts avoid burnout. 

The Biden administration’s Executive Order 14028 on improving national cybersecurity may drive this need for increased security information sharing, enabled by vendor-led threat intel cooperatives. But government-led information sharing will likely take a while. Expect it to start through vendors sharing data from across their own customer bases. Eventually, we can hope to see governments providing intelligence as well, taking a more assertive role against cyber crime. 

DevSecOps principles will be adopted faster than DevSecOps as a formal practice 

Like Agile development or DevOps, DevSecOps has its own manifesto, conferences and T-shirts. But it hasn’t gained the formal traction that Agile and DevOps have, and the question to ask is, “will it?”. Truly, whether an organization “adopts the orthodoxy” or follows its principles to just do security better, DevSecOps is essential. The reality is any fortune 1000 company already has a need for DevSecOps, whether they know it or not.

Without embracing DevSecOps as a formal movement, many organizations have adopted the key principle of moving security from the last step of software development to the first – bringing  responsibility to developers.

Basic security diligence is your new perimeter

If the perimeter is what keeps attackers out of your systems, and the perimeter can’t be tied to a single layer of security or part of your infrastructure, then your perimeter is you – the actions you take as a security professional to keep cybercriminals at bay. Rather than the perimeter focus that’s about protecting a virtual space, security teams should be starting with the individuals moving within that space. 

There’s no silver bullet or magic pill to protect yourself from a breach, but when you focus on best practices such as MFA, full patching, and asset identification, you can prevent a breach from becoming a major one.

##

About the Author

Ryan Kovar 

Ryan Kovar is a distinguished security strategist and leader of Splunk SURGe. With over 20 years of experience cybering, Kovar has done everything from pulling miles of CAT5 cable on an aircraft carrier to learning that he didn’t want to be a malware RE. Most recently, he worked at the Defense Advanced Research Projects Agency (DARPA) on a team dedicated to detecting and mitigating advanced threats. Kovar then moved to Splunk as a Distinguished Security Strategist where he teaches hunting, attempts practical security research, and solves fun problems for folks around the world. Kovar loves Bernese mountain dogs and wire data, and despises printers.