Virtualization and Cloud executives share their predictions for 2016. Read them in this 8th Annual VMblog.com series exclusive.
Contributed by RSAC Advisory Board Members
RSAC Advisory Board Security Industry Predictions for 2016
2016 will be the year of “extortapalooza”
Extortion attacks are nothing new – for example, take the recent situation with Charlie Sheen having to announce that he is HIV+ after paying out millions of dollars to people who knew about his status. Sheen’s case is a bit sensational, but this doesn’t happen only to celebrities; it can happen to companies of all sizes through crypto ransomware or DDoS attacks and to those on Main Street if their identity is stolen. In 2016, we will see a rise in extortion attacks across multiple industries, but especially within healthcare – according to Reuters, medical information can be 10 times more valuable than a credit card number. Schemes will expand to medical devices such as diagnostic equipment, therapeutic equipment, and life support equipment, wherein attackers will lock it so it becomes inactive until a ransom is paid. That’s scary to think about when some of these devices are essential to keeping someone alive.
Wendy Nather, Research Director, Retail Cyber Intelligence Sharing Center
Microservices will change the build vs. buy debate – 2016 a good year for DevOps
Organizations have always faced the dilemma of building or buying application security components. Traditionally, companies roll their own because 1) they believe they can do it better, and 2) they don’t want to share vulnerabilities with other companies. In 2016, microservice security offerings will begin taking hold. Identity management and customer data – the crown jewels of any organization – will be increasingly migrated to specialized cloud services. Solutions will come from a diverse and new set of vendors, from Parse (acquired by Facebook) to Salesforce.com. Developers will insert vetted services and code into their own software, avoid building from scratch, and obtain a security level better than most homegrown offerings. And, for companies who insist on build-your-own, relief is coming in 2017 when container technologies will allow in-house teams to practically manage and integrate microservices of their very own.
Benjamin Jun, CEO, HFV Labs
Industrialization of ransomware
Many cybercrime groups are running like companies, and they can quickly move to build out a ransomware infrastructure. For most people, it isn’t shocking anymore when their credit card data gets stolen. The most frustrating part for most victims of credit card theft is that they’ve forgotten all the services associated with that credit card, and they now have to go back into lots of websites and update everything. It’s a big pain and time intensive, but the damage is typically short-term. This differs from data that might be embarrassing, invasive or harmful to a person. Stolen healthcare data doesn’t don’t have an expiration date, and we are only just starting to realize the implications of this type of being in the hands of attackers. Today, organized crime groups may steal data that is currently difficult to monetize and furthermore, steal it at a time when there may be less security investments in those sectors (i.e., financial services organization in general are harder to break into because they generally have larger security budgets and security professionals on staff, while the information security budgets of healthcare organizations are typically smaller have been heavily weighted towards compliance). Stealing this type of data, like someone’s medical history that does not expire and cannot be reset, unfortunately gives attackers the luxury of time to build an infrastructure to monetize that data.
Herbert “Hugh” Thompson, Chief Technology Officer, Chief Marketing Officer, Senior Vice President, Blue Coat Systems
Data and information will continue to be weaponized
Use of data as weapon will be a major problem in 2016. In the past, data has been taken, destroyed or encrypted, but increasingly we’re seeing breaches during which data is leaked publicly in order to cause significant damage to a business, reputations, or even the government (e.g., Sony, Ashley Madison, etc.). Criminals and hacktivists are now stealing data and threatening to place it on public websites for others to see. In conjunction with this, hackers are building massive databases that include multiple types of data (insurance, health, credit card) to present a “full picture” of an individual. It’s one thing to have your data stolen and another to have it used against you. We’ll continue to see individuals’, corporations’ and public entities’ info used against them as a weapon in 2016.
Dmitri Alperovitch, CTO and Co-founder, Crowdstrike
Hackers will go “quiet”
Since the Sony hack last year there have been a few high-profile attacks, but nothing quite as loud or full-on destructive. Attackers have been much quieter in 2015 in signaling their capabilities and broadcasting infiltrations and this will continue into 2016. Instead of the big showy attacks that post the data and embarrass companies, the use of more quiet attacks means the public will hear less, while boards and executives will hear more – not about the attacks themselves but about the effects of the hack. It’ll be more “Houston, we have a problem” with less insight into how the attack was accomplished and how the hacker obtained any value from what was done. Hackers will become more insidious in nature and in practice.
Todd Inskeep, Principal / Director of Commercial Consulting, Booz Allen Hamilton
##





