Opens in a new tab
vmblog logo 2024 wht (updated)

ThreatModeler 2022 Predictions: Cloud Migration, Zero-Trust Architecture and Ransomware: The Year Ahead

Share: 

David Marshall | Published: January 17, 2022

 

Industry executives and experts share their predictions for 2022.  Read them in this 14th annual VMblog.com series exclusive.

Cloud Migration, Zero-Trust Architecture and Ransomware: The Year Ahead

By Archie Agarwal, Founder & CEO, ThreatModeler

IT infrastructure has been in a period of intense transition, exacerbated widely by the global disruptions brought on by the events of the past two years. Remote work, hybrid work, digital transformation and general societal disruption have all played into the challenges we face today.

Ransomware attacks are at a record high, and are scoring record payouts, according to data from the US Treasury Department. As recent attacks centered around the now infamous log4j vulnerability come to light, it’s clearer than ever that our networks are fundamentally insecure. As such, it is important to evaluate the threat landscape and prepare for what challenges lie ahead in 2022. With that in mind, here are three key themes that one can expect to play out and the direct impacts they may have in the year ahead.

Rushed Cloud Migrations

The pressure of the business imperative to adopt cloud at rapid speed during the Covid period will begin to unravel as it becomes apparent security slipped through the cracks in rushed migration. As a result we will witness the rise of huge breaches due to simple cloud security misconfigurations and permissioning errors.

The global shift to remote and hybrid work has rapidly and oftentimes insecurely spurred cloud adoption. Just as cloud migration solution providers arose to meet those needs during the pandemic, 2022 will see startups based on automation of cloud configuration rapidly emerge, offering permission analysis and remediation platforms to correct market insecurities.

The shift towards Zero Trust

High-Profile breaches in the past year have continued to cast a doubt over the necessity of VPN technologies. 2022 will likely see the exposure of more vulnerabilities associated these popular VPNs. The discovery of these vulnerabilities will feed into existing trends, leading to a rise in Zero Trust architecture. 

With VPNs acting as public doorways on the Internet giving an opportunity for would-be bad actors to access enterprise operations, the realization that Zero Trust architecture offers the opportunity to cloak entry points will become more understood and adopted. As this occurs, the industry will accept that the fortress and moat security mentality that VPNs represent has failed, enabling Zero Trust solutions to become mainstream.

The Evolution of Ransomware Groups

Ransomware will continue to rampage, and the exorbitant payments made to criminals by organizations and insurers to decrypt and retrieve data will likewise continue to rise. This pattern will start to raise serious questions as the increased success of these activities enable criminal gangs to become wealthier, further professionalize and invest ill-gotten gains into faster and more effective weaponization of exploits.

Due to this lucrative feedback loop, we will hear more stories of criminal ransomware groups with VPs of product and organizational structures mirroring legitimate organizations. All of these developments will lead to further public debate around paying extortionists and ransomware.The continued rise in cybercrime activity will undoubtedly lead to new sanctions, prosecutions, and higher bug bounties. However, all of these tools fall squarely in the reactive camp and provide virtually zero value in mitigating future threats.

To achieve security, the industry needs to shift to a proactive approach in identifying, predicting and defining threats across the entire attack surface to minimize overall risk. Organizations must enact solutions which are present across the enterprise software development life cycle and not abandoned in the face of adversity or catchy new trends. 

In the short term, we will continue to see the results of a reactive cybersecurity posture. If the industry fails to adapt by developing a proactive approach to secure product development, cyber attacks will continue to increase in severity and scope. In other words, without proactive solutions, you can be sure that you’ll be reading a similar article next year.

##

ABOUT THE AUTHOR

Archie Argawal 

Archie Agarwal is Founder & CEO of ThreatModeler, a leader in securing cloud infrastructure from design to deployment. As CEO, Archie enables ThreatModeler to deliver true DevSecOps by providing automated, continuous visibility into flaws in application design. Archie has over 20 years of experience in risk and threat analysis, with a background encompassing over a decade of work with international web application security bodies, OWASP and WASC, security strategy transformation, threat modeling awareness, and training IT professionals to overcome security challenges. Archie is a Certified Information Systems Security Professional (CISSP). He is also SANS GWEB certified, and a member of the Forbes Technology Council.