Industry executives and experts share their predictions for 2022. Read them in this 14th annual VMblog.com series exclusive.
Time to Tackle the Ransomware Elephant in the Room & Other 2022 Predictions
By Casey Ellis, CTO, Founder and Chairman, Bugcrowd
2021 brought many challenges with COVID-19 accelerating digital transformation at an unprecedented rate. IT teams were rushing to find solutions that could grant access to assets on the internal corporate network for remote employees so they could remain productive while working from home. Unfortunately, speed is the natural enemy of security, and anytime new technologies are implemented on the fly, there will be exploitable vulnerabilities left behind. This makes remote workers a prime target for adversaries as compromising an employee will grant potentially unfettered access to the corporate network if the proper tools aren’t in place. This is an obstacle many organizations will continue to face as we head into 2022.
Here are some other trends to keep in mind as we ring in the new year:
Global Cyberattacks from Nation-State Actors Posing Greater Threats
The macro-trend I’m most alarmed by today is the fact that attackers don’t seem to care about getting caught anymore. We have seen an increase in temerity of attacks by nation-states, such as the Russian attack on SolarWinds, and seen their attack tactics shift from targeted, stealthy operations into opportunistic hacks for potential future uses, such as the attacks attributed to HAFNIUM.
Such a brazen approach hasn’t been a common tactic of nation-states in the past, but now seems to be the status quo. In part, this trend may also be due to a destabilization of the international relations climate stemming from Covid-19, as well as work-from-home forcing core business services out onto the Internet to facilitate employee access.
Broadly speaking, we should see China as a rising cybersecurity threat on the international stage. That has been the case for some time in terms of their economic, defense, and military posture, but 2021 has quite clearly demonstrated that the relationship has deteriorated into a sort of Cold War, with espionage playing out in the cyber domain.
Now That We’ve Mastered Work-From-Home, It’s Time To Head Back To The Office
The rapid and globally synchronized shift to work-from-home was hugely impactful from a security attack surface standpoint, but we were collectively focused on the same goals. As the dust begins to settle on the pandemic a new threat emerges: Technological disruption as a result of a transition to hybrid work, where the goals are widely varied and generally less defined. As a result, the home is now viewed as part of the attack surface, and this introduces such a vast number of new variables that it’s safe to say that we don’t really know how that works yet. This is a disturbing development because it is so easy to determine the home address of a potential target these days, bringing the employee’s house into scope as a newly vulnerable attack surface.
Similarly, how should security measures work to protect Zoom video calls? We are all working on these same problems, but there is no easy solution because the approach to hybrid work differs for every organization. Anytime complexity increases, it also increases the potential attack surface.
We have seen increased interest in consumer IOT and home router zero-day exploits, with attacks following close behind. In the past, the home as an attack vector was rarely interesting to sophisticated nation-state attackers or cybercriminal gangs, but we should expect to see more activity in this area over the coming year.
Tackling the Ransomware Elephant in the Room
Ransomware has been working well for the bad guys for quite some time now, but in 2021, it established itself as a highly effective and lucrative criminal business model. Just like any regular business, things that work tend to accelerate, receive investment, and evolve, and we should expect to see a continuing acceleration in the adoption of ransomware tools by attackers, including the criminal enterprises funded (or shielded) by nation-states.
The ransomware problem is particularly acute for the healthcare sector. Shutting down computer networks at hospitals and clinics can quickly spiral into a case of life or death for patients, and the increased awareness of healthcare’s critical nature makes it an attractive target to hold to ransom. I hope this predicament will force providers to innovate by developing a new category of security solutions to disrupt the economics of ransomware.
We saw a promising development in Q2 of 2021, when the insurance firm Lloyd’s of London retracted their insurance policies for ransomware payments in France. Lloyd’s adjusted their policies to not pay ransom costs anymore, likely because their actuaries told them it was irrational to insure against this problem – We’re just not very good at preventing it yet. That step will likely signal big changes coming for the insurance, fintech, and security industries in the year ahead and beyond.
Priority #1: Getting Our Heads Out of the Security Sand
Perhaps the most encouraging trend of all may be the disruption of indifference to the security problem that we have seen from leaders of organizations across all types of industries and regions. 2021 has very clearly demonstrated that the cyber boogie-man is real and active, and could attack them next.
Many organizations are still stuck in “ostrich to risk management” – Hoping that by burying their heads in the sand and ignoring the problem, it will cease to matter. However, the steady increase in attacker activity throughout 2021 is continuing to erode this a viable strategy, the cybersecurity problem is growing, and breaches can happen to anyone next.
Consumers are weighing in too, becoming more wary about security hacks and breaches. In turn, that awareness is influencing buyers to demand products that will make security a prime feature and market differentiator.
##
ABOUT THE AUTHOR
Casey is the Chairman, Founder, and CTO of Bugcrowd. He is a 20+ year career veteran of information security, and has been inventing stuff and generally getting technology to do things it isn’t supposed to since childhood. Casey has worn a variety of professional hats, working as a pentester, security/risk consultant and solutions architect, Chief Security Officer, and most recently as a career entrepreneur and company leader. Casey pioneered the Crowdsourced Security as a Service model, launching the first bug bounty programs on the Bugcrowd platform in 2012, and co-founded the disclose.io vulnerability disclosure standardization project in 2014. Casey is a sought-after industry visionary, media commentator, and keynote speaker, and has presented at DEF CON, Black Hat, RSA Conference, Techcrunch DISRUPT, Shmoocon, ENISA, Usenix ENIGMA, Nullcon, Derbycon, SOURCEConf, AISA, AusCERT, and others. He has advised the US Department of Defense, Australian and UK Intelligence Communities, and US House and Senate legislative initiatives including pre-emptive protection of cyberspace ahead of the 2020 Presidential Elections. A proud native of Sydney, Australia, Casey lives with his wife and two kids between Sydney and the San Francisco Bay Area. He is happy as long as he is pursuing potential.






