Industry executives and experts share their predictions for 2022. Read them in this 14th annual VMblog.com series exclusive.
Trends & Predictions: Shifting Privacy Landscape Increases Security Complexities
By Erkang Zheng, Chief Executive, JupiterOne
As any security professional will tell you, 2021 has been the year of ransomware attacks. Over the past year we have seen a bevy of attacks that have shifted public policy, highlighted our lack of talent in the security industry and drawn attention to our patchwork of privacy measures. As we make ready for a new year full of fresh challenges, security leaders must remain strategic and diligent to face the fast-evolving threat in the year ahead.
Privacy Protections Add Complexities and Vulnerabilities
The first challenge I see the security industry having to grapple with is the fragmentary focus on privacy. I anticipate that this will only get worse in the foreseeable near-term future. At one point we were hoping that compliance was going to get simpler, but it doesn’t look that way anymore. Seemingly every state and country has come out with their own unique privacy regulations. The European Union has its GDPR regulatory framework, the state of California has CCPA, and even China and Hong Kong each have their own rules. It’s a mess from a security standpoint because there is no standard to build on and that leaves room for errors. This patchwork makes security jobs more challenging as security professionals must understand and implement the disparate privacy and compliance regulations from around the world and jerry-rig them together for each region their company operates in.
Ideally, there would be an international consortium to address these diverse privacy rules from around the world. New privacy rules create complexity and not just from a compliance standpoint. Security is often a game of details, so as things become increasingly complex, it introduces more things that can go wrong and more pathways for malicious actors to break into the enterprise. We need to see greater simplification on the process side, driven by unification of regulations. A lot of things sound great on paper, but how practical is it to implement security across so many different regulatory frameworks? At the very least, national rules will need to come together for organizations to implement a cohesive privacy framework for each country. By not reaching some consensus about privacy, we are introducing greater risks for everyone to stand up adequate security protections.
Security Resource Shortages
Another clear trend we will continue to see in the security field is a human resource shortage. This is absolutely a trend with the caveat that we are potentially looking for the wrong skill sets in security. We should expect to hire more security folks in engineering and automation, compared to the traditional security analysts who are the eyes on the screen doing the analysis by examining the data themselves.
Instead, we will begin to see a lot more security engineers who write scripts and use APIs to do analysis through automation. Security practices and tooling are changing to be more cloud-native which means there is more automation and data-driven decision making. These shifts are a positive thing as it provides greater efficiency and efficacy for continuous cyber governance. The next step is adjusting our hiring to account for these technology shifts. Practically, this means hiring security talent with engineering and automation skill sets in addition to security analysis and testing.
The related challenge to this is how do we incentivize people to do the right thing? For instance, if a CISO in the public sector wants to hire a top-notch security engineer, how can that public agency ensure that the new hire gets comparable benefits as if working in the private sector? We are asking a lot when our pitch is: “Please take a significant pay cut to work for a public agency, because it’s the right thing to do.” The challenge is that this issue doesn’t just involve paying equitable salaries. Organizations will need to reform their whole brand, image, culture, and mindset to attract new talent and give those people new opportunities on the job. Federal, state and local governments will need to up their game on technology adoption because talented people want to work on the cutting edge where they can be exposed to new technologies in their roles.
Vendor Consolidation Growing
Speaking of cutting edge technologies, most enterprises have too many ‘best-of-breed’ solutions. Much like our need to implement privacy standards to reduce complexity, enterprises will begin consolidating their security stacks to simplify their operational systems. The theme should be getting back to the basics.
By “the basics,” I mean that best-of-breed solutions are still needed for the most important security operations, but the average large enterprise already has some 50 to 70 big tool vendors. Many teams would benefit from consolidating their security vendors. You don’t need the best tool for every niche use case, especially when that creates complexity and leaves more room for mistakes. The challenge is two fold, not only does a plethora of tools leave room for mistakes in the stitching of the various solutions together, it often means that the data is spread out in disparate locations. In security, knowing what’s going on is often the most important element. Businesses need tools that are good enough to allow users to have a cohesive view of things, rather than everything being siloed. As a result, we should expect to see the number of security vendors at large organizations reduced by 20% to 30%.
The Need for Insurers to Crack Down on Ransomware
The final trend I am seeing is a continuation of the Insurer’s crack down on ransomware. With many attacks having been linked to state-sponsored cyber organizations or large criminal syndicates, we cannot afford for ‘ransomware-as-a-service’ to become the norm, literally or figuratively. To some extent we have already seen insurance companies coming out with hard policies to address ransomware, either by not paying out the ransoms, or demanding very strong security requirements to issue their insurance policies. I think this is a good impulse.
For insurance companies, money always talks, and until there is a breach, security is preventing nothing. The only driving factor is compliance or the monetary factor of insurance firms having very hard policies regarding cybersecurity protections.
Of course, the security field remains in constant flux, which makes it difficult to decide where to focus resources, energy, and attention. Stepping back a bit, we would do well to strengthen the ties between security organizations, technology vendors, service providers, and our public policymakers. Society’s best interests are only served when its leaders implement sensible rules and regulations that can protect user privacy while still promoting greater commerce and cooperation among disparate organizations worldwide.
##
ABOUT THE AUTHOR
Erkang is a cybersecurity practitioner and founder with 20+ years across IAM, pen testing, IR, data, app, and cloud security. An engineer by trade and entrepreneur at heart, he is passionate about technology and solving real-world challenges. He is the former CISO, security leader at IBM and Fidelity Investments. Erkang holds five patents and multiple industry certifications.






