Industry executives and experts share their predictions for 2019. Read them in this 11th annual VMblog.com series exclusive.
Contributed by Alejandro Lavie, Director of Security Strategy, Flexera
Major Endpoint Breach in 2019 Due to Unmanaged Software; Weaponised IoT Attack
Predicting the future is a dangerous activity. Somewhat unreasonable expectations are created, and some experts argue that reading predictions can influence outcomes of those protagonists by creating the future itself. Predicting the future goes against our deepest human nature characteristics because it’s founded on incomplete information. Humans don’t like to make decisions based on uncertainty, but we can’t deny that it’s possible to anticipate certain events based on recent information, trends in data, changes in patterns and statistical analysis.
When it comes to cyber security, it’s pretty obvious that things are going to get worse before they get better. The proliferation of software in everything we own, use and bring into our lives, and the explosive growth of IoT devices isn’t matched to our ability to develop more secure software – or keep up with the bandwidth needed to keep that software up to date, our networks monitored, and our activities reasonably protected.
Coupling those facts with recent discoveries and reports in specialised circles in the dark, deep and open Web, Flexera can dare to predict a couple of major incidents in 2019:
1. Before 2019 ends, a major breach caused by a vulnerability in unmanaged software in the endpoint will be widely reported in the news. Sounds like nothing out of the ordinary, right? But the key here’s the “unmanaged software in endpoint” component. It continues to be a reality that most organisations focus on patching the noise-makers, the squeaky wheels (Microsoft, Adobe and Java) but disregard other unmanaged software in endpoints that still have vulnerabilities with active exploits in the wild.
The lack of resources and visibility creates a problem to fix this, and the time spent patching has to be limited to the perceived major applications – which more often than not, are misaligned with what the real threats are for organisations.
In 2019, we’ll likely find out that an endpoint with rogue software is breached, affecting the whole organisation. The call to action will be that there had been a patch available for that vulnerability for months, but it had not been applied.
2. 2019 will be a year where IoT will be weaponised to attack major infrastructure and governments, and cause disruption for citizens. The danger’s been present for a while, and reports suggest that rogue actors and nation states have infiltrated key systems and are waiting to be activated at the right time to cause disruption.
From utilities to medical facilities, we know that IoT is everywhere and it doesn’t have the same level of secure development that other pieces of enterprise software. Many of these devices are left unmanaged, opened and exposed with default credentials, running on decades-old operating systems, with little management.
But more important than predicting the future, we should be focused on influencing it. With visibility in endpoints and IoT, intelligence relative to our managed and unmanaged software, and automated process to aid when resources aren’t available, organisations can reduce the exposure to these risks and many others. This isn’t a new concept, but definitely one where organisations still need help.
##
About the Author
Alejandro is the Director of Security Strategy for Flexera’s Software Vulnerability Management portfolio. He has 20 years of consulting and business development experience in four countries, focused around enterprise software in cybersecurity, IT operations, IT service management and optimisation.






