Industry executives and experts share their predictions for 2023. Read them in this 15th annual VMblog.com series exclusive.
2023: Evolving Cyberattacks and The Demand for Security Automation
By Bud Broomhead, CEO of Viakoo
Reflecting on the past year, we have seen cybercriminals’ tactics evolve along with their ability to breach an organization of any size and any industry. For example, Medibank Private Ltd confirmed 9.7 million customers data had been accessed by bad actors, Uber paid $100,000 to cover up a data breach of 57 million users, and Russian adversaries leaked 500GB of information from The Los Angeles Unified School District (LAUSD).
Looking ahead to 2023, we expect to see bad actors continue to leverage innovative technologies to become savvier with their attacks, and organizations will need to assess their current security protocols, especially for their IoT/OT devices.
Ransomware And Malware Will Be More Industry Specific
We’re used to seeing a great variety of organizations forced to contend with relatively similar strains of malware, however, we’ve already encountered examples of malicious software specifically designed for target systems in a specific industry, including banking and industrial control systems for water supplies. The potential for cascading negative outcomes in key sectors like this amplifies the power of an attacker that gains control of such systems, so malicious actors will continue to devote more resources to this kind of attack.
Deepfakes Used for Social Engineering
As the technology for deepfake videos grows both more sophisticated and accessible, malicious actors will leverage those tools to impersonate people in positions of authority to execute their scams. Instead of phishing emails that simply spoof an email address, we’ll see increasingly more hyper-realistic impersonation videos, opening a new and extremely effective tactic for criminals to steal from their targets.
Bot Eradication vs. Mitigation
To deal with a rapid and growing volume of cybersecurity threats, tactics used by security teams will focus more on finding and eliminating sources of malware, typically an infected botnet that is orders of magnitude smaller than the attack vectors they create by spreading their malicious software (a single infected botnet can create billions of attack vectors). The current focus on bot mitigation will continue, but we will see more efforts on bot eradication.
The Demand for IoT/OT Security Automation
As we all know, current economic headwinds have forced many tech companies to layoff their employees. Staffing and resource challenges will become even more pronounced as cybersecurity threats, especially IoT/operational technology (OT) threats, multiply in volume faster than teams can keep up. To contend with this, we will see widespread implementation of IoT/OT security automation among organizations of all types.
The Emergence of Cloud-Based Composable Workflows
Another outgrowth of the staffing challenge that organizations will face moving forward will be the emergence of cloud-based composable workflows. Essentially, these are a combination of solutions that can be quickly and dynamically engaged in the cloud by non-technical users, rather than specific applications and software. This will enable everyday users to work far more efficiently than before as they use the tools based on their own workflow rather than being constrained by the capabilities of a particular business application.
Next Steps
As cyber threats become more sophisticated and industry-specific, we will see adoption of IoT and OT security automation, cloud-based composable workflows, and increased focus on bot eradication. As a result, government priorities will shift, and companies’ security strategies will be forced to change. Organizations that fail to analyze their current cybersecurity strategies and leverage new security automation technologies in the coming year will get left behind.
##
ABOUT THE AUTHOR
Bud Broomhead is the CEO of Viakoo, a leader in IoT device remediation. He is a serial entrepreneur who has led successful software and storage companies for more than two decades. He has experience delivering computational and storage platforms to the physical security space for over seven years, with an emphasis on infrastructure solutions for video surveillance.






