Industry executives and experts share their predictions for 2018. Read them in this 10th annual VMblog.com series exclusive.
Contributed by Arthur Braunstein, Vice President, U.S. Sales and Netta Schmeidler, Vice President, Product Management at Morphisec
Attacks Will Increase
Arthur Braunstein, Vice President, U.S. Sales
A consultant or analyst will get paid for the following unhelpful advice: “The vendor space is crowded. You should assess your needs and come up with a strategy based on people, process and technology. Invest in visibility. True prevention does not exist, so focus on speedy detection and response. Assess 3rd party risk. Do NIST. Tell the board there are no guarantees.”
A practitioner will offer something more useful: “Reduce your attack surface. Recognize that complex security tools increase the attack surface and create the potential for human error. Simplicity does not mean ‘platform’. Use best-of-breed controls designed for specific threats. Implement prevention. Ensure a layer to protect OS memory is part of your defense-in-depth.”
Adversaries will refine the ways they monetize attacks. They will exploit cracks in regulatory and reporting schemes to demand higher ransoms, leveraging their ability to halt operations–for example at the end of a financial quarter–or destroy customer confidence. They will put at least one company out of business, to ‘send a message’, and permanently damage others.
The frequency, ferocity, scale, and speed of attacks will increase. They will take on an expeditionary character, employing advantages of timing. For example, as the damage from one attack is being cleaned up, another massive attack will follow. Sleeper attacks will be staged in advance, within enterprises and innocent botnets, for activation at zero-day.
Vendors will be defined by two personas: ‘me-to’ companies; and disruptors. The ‘me-too’ companies will claim to be innovators. But they will offer no more than minor improvements to a static defensive paradigm that does not threaten adversaries. The disruptors will design products that nullify the advantage of adversaries and put their cybercrime enterprises at risk.
Netta Schmeidler, Vice President, Product Management
2018 will be crunch time. Up to now, despite the sheer volume of attacks, organizations have been biding their time, not committing to any specific technology, instead adding on some mediocre modules from existing vendors. In 2018, the magnitude of the public impact of attacks will force organizations to really invest in cyber defense: from the boardroom down. GDPR will be a driving force in this direction, but not the only one.
And of course we’ll see more attacks: More IOT, more supply chain, even more ransomware than before. The attacks will be disabling, in a public manner.
##
About the Authors
Arthur Braunstein is Morphisec’s Vice President of US Sales. Arthur has more than 25 years of executive management and sales leadership experience, including over 10 years in the data and cyber security industry.

Netta Schmeidler, VP Product at Morphisec, has more than 25 years of experience delivering complex enterprise applications and managing global development groups and product teams. Her broad expertise includes all aspects of defining, building and successfully bringing solutions to market. She received an MBA from Tel Aviv University, and a BSc in Computer Science from Hebrew University.






