Industry executives and experts share their predictions for 2022. Read them in this 14th annual VMblog.com series exclusive.
2021 was a surprising year for cybersecurity – and surprises will continue in 2022
By Thanassis Avgerinos, co-founder and VP Engineering, ForAllSecure
Cybersecurity made the news numerous times during 2021, and you know that is less than great because the whole point of security is to stay away from making headlines. In 2021, we witnessed a broad range of attacks ranging from ransomware to supply chain attacks and from data leaks to common logging libraries being exploited in the wild (Colonial Pipeline, SolarWinds, Twitch, Codecov, Log4j – just to name a few – are now codewords that will be imprinted on our brains for a long time). During Pwn2Own-like contests this year, we saw every major piece of software getting hacked, sometimes multiple times by different teams. Last, but not least, the scarcity of talent in the field is striking and the 500 to 1 security professionals to developers ratio did not improve during the “great resignation”. To summarize, as we are moving towards 2022, we seem to have the definition of a project manager’s nightmare in our hands with numerous hard-to-scope challenges permeating throughout the industry, not enough resources to handle them, and very little time to fix them.
Using 2021 as the backdrop for our next year predictions, we can safely say that surprises will continue, and we will see several new headlines in the coming year. We present below our guesses for what these headlines may look like.
A major cryptocurrency will be hacked within the next few years. The value of cryptocurrency has dramatically increased over the past few years. And as the value continues to rise, so too does its value to adversaries. But this currency lives on a network with no “armed guards” protecting its vault. It’s not a matter of if, but when, vulnerabilities will be found. And the result could cause a mass evaporation of funds. Bug bounty programs are a start — but there is still much more to do in the way of shoring up the security posture.
Supply chain attacks will continue to rise. This year, the SolarWinds attack reinforced the importance of accessing where the keys to the data are, not just protecting the data itself. At the same time, development teams continue to introduce more technologies into their stack to get the “best tool for the job” and enhance their agility. This trend, coupled with a continuously increasing reliance on opensource software creates a growing challenge for organizations. As a result, the number of supply chain attacks will continue to increase, and it is likely we’ll see more large-scale attacks come up in the coming year.
Wonderful depiction of reality by https://xkcd.com/2347/
Out-of-date devices will continue to be massively exploited. Updating software on devices – not just general-purpose computers – is a time-consuming process. In some cases, it’s not even possible because “regular updates” were not part of the product design. We entrust such devices with holding our data and sometimes provide them with access to trusted networks without too much thought. Combined with an ever-increasing number of networked devices, deploying attacks against such devices becomes even more appealing because of the low-effort / high-reward tradeoff. Better upgrade processes and continuous security testing throughout the development lifecycle will help, but that is still a few steps away for several products.
Predictions about future attacks can make the future seem bleak, but we believe that these upcoming challenges are opportunities to innovate across the board: in security tools, training, automation, and the software development process. Let’s all work together to make 2022 a less surprising year!
##
ABOUT THE AUTHOR
Thanassis Avgerinos, co-founder and VP Engineering, ForAllSecure
Thanassis is an expert in program analysis, testing, and software security with over a decade of operational and academic experience. Prior to co-founding ForAllSecure, he was a researcher at Carnegie Mellon University, working on developing the first Mayhem prototype. Thanassis holds both a Ph.D and Master’s degree from Carnegie Mellon University and a Master’s and Bachelor’s degrees from the National Technical University of Athens, all in Electrical and Computer Engineering.






