Site navigation

2022 Cybersecurity Predictions: What Can We Expect?

Michael Behr

,

2022 cybersecurity
What lessons did we learn from 2021, and how can we apply them?

If 2022 is anything like 2021, cybersecurity personnel will be extremely busy this year.

There is little doubt that the previous two years bear high-tide marks for ransomware. It is simple enough to find evidence of this. From high-profile breaches to major increases in attacks and attempted attacks, criminals are going where the money is, and that’s online.

The pandemic drove an acceleration in the digital transformation, connecting more physical infrastructure to cyberspace. This inevitably increased the surface area available for threat actors to target and made the consequences of a breach more serious. We have already seen how cyberattacks can affect physical systems, such as the Colonial Pipeline attack.

With cyberattacks presenting a major risk to all organisations, staying one step ahead of the threat actors is vital. To understand how the previous year will inform the 2022 cybersecurity landscape, DIGIT spoke with Chief Security Strategist at Bitdefender Catalin Cosoi.

While making predictions about the notoriously murky cybercriminal ecosystem is difficult, he mentions one principle that can guide us.

“If somebody is vulnerable, and has money, why not take it? That’s going to be their motto,” Cosoi warns.


Cybercrime Matures

The seeds of the 2022 cybersecurity landscape can be traced back to the pandemic. Organisations, almost overnight, had to start working remotely. This meant delivering a massive digital transition in a matter of weeks.

“Some institutions had to digitalise a lot faster than they would be comfortable with,” Cosoi notes. “Since not all of them were security prepared, this opened the gap for the attackers.

“And obviously, mistakes have been made as security was not necessarily one of the most stringent concerns,” he adds.

This led to many cybercriminal gangs pivoting away from targeting individuals to go after larger organisations.

“A lot more ransomware families were focused on corporate victims because companies or state institutions have to function,” Cosoi says. After all, for health care providers or energy infrastructure, downtime is not an option. Cybercriminals thrive on snap decisions, and when every hour counts, the best decision is, sadly, to pay the ransom.

“Obviously, it was a very lucrative business for the ransomware authors,” Cosoi notes.


The Fall of REvil

However, the salad days of 2021 may have inadvertently caused problems for ransomware groups.

“Some of them actually started to become a bit greedy, especially the ones that offer ransomware as a service,” Cosoi explains.

In many ways, the story of REvil is emblematic of the trends of 2021 and what we can expect from 2022. It went from perpetrating some of the year’s biggest cyberattacks to having its members arrested and its infrastructure dismantled.

Perhaps the biggest reason behind its downfall was that it drew too much attention. In part, this was due to the structure of a ransomware gang. A core group of coders create the malware, while affiliates perform the attacks.

“Some of the attackers targeted very high-profile victims, such as Kaseya or the Colonial Pipeline,” Cosoi explains. “This brought a great deal of media attention on the threat posed by ransomware, from the media, governments, and law enforcement.”

While the exact chain of events and motivation is known only to REvil’s members, what followed was a phone call between Biden and his Russian counterpart, Vladimir Putin, in part to discuss cybersecurity.


Recommended


Not long afterwards, REvil’s dark web portal went down, with a representative claiming they had taken it down after a member went missing, presumed arrested or even dead.

Bitdefender played its own part in reversing REvil’s fortunes. They created the universal decryptor for the Kaseya attack that helped victims unlock their data and provided key insights to the investigation.

What followed was a series of arrests in Romania, South Korea and other countries, before Russian authorities made several more arrests.

As such, this may well serve as a warning to overambitious criminals in 2022. But it also helps inform their choice of targets.

“If hackers stay away from very high profile or critical infrastructure victims, they’re going to have a very nice and profitable 2022,” Cosoi says.


Be Cautious

So how will this affect cybercrime in 2022? While the demise of REvil is ultimately good news, there is no shortage of other groups looking to take its place in the ecosystem. The current digital landscape offers a target-rich environment for anyone with ambition and capabilities.

However, it is likely that cybercriminal groups will make two changes this year, according to Cosoi.

“They’re going to target companies that will pay a lot of money – tens of millions and more. But they’ll try to stay away from targets that are highly visible – they’ll be more selective with their victims.

“The second thing is they’ll be a bit more selective about whom they work with,” he adds.

As such, any ransomware groups wanting to avoid REvil’s mistakes will need to ensure they only work with carefully vetted associates. This may make scaling difficult in the short term, as the groups are slow to onboard potential members.

That isn’t to say that there is a lack of potential associates with the skills and desire to make easy money.

“For some of these ransomware families targeting high-profile victims, the actual attack wasn’t brain surgery,” Cosoi notes. “Sometimes it’s just the compromised password that you can find online, right? Other times it was just very easy password that can be brute forced.

“You can still make a lot of money with minimal technical know-how.”

Of course, all this is assuming cybercriminals learn their lessons. But the lure of easy money consistently draws people to make costly mistakes.

The story of REvil is similar to its predecessor group, GandCrab. This too saw overambitious affiliates target a large volume of targets, catching the attention of law enforcement. GandCrab ultimately disbanded and reformed later as REvil.

And history often repeats itself.


The Tech Factor

Scaling is an issue that faces both cybersecurity and cybercriminal groups. New technology offers a way for both sides to get round this. Automation, for example, lets hackers target more victims and move through networks faster.

“On the attacker side, there’s a lot of tasks that could be automated,” Cosoi says. “This is something that they will probably develop in the next years.”

Deepfakes are another interesting technology of use to hackers. With trust being an essential component of social engineering attacks, the ability to accurately mimic a colleague, friend or superior’s voice or appearance could help convince a target to provide valuable information. After all, we might ignore an email from the CEO telling us to transfer $1,000 to an unknown account, but would we ignore a phone call from them?

“If you can clone a person’s voice or their face, that will take social engineering to the next level.”

The rapid digitalisation of the economy in the face of the pandemic means technology has changed the landscape. On the one hand, this provides opportunities for businesses. On the other, it creates vulnerabilities that hackers can exploit. Technological changes will help define the 2022 cybersecurity landscape.

“What we’re predicting in the near future is a lot more criminals looking to target cloud infrastructure,” Cosoi warns.

“With companies migrating to the cloud, there’s going to be a level of compliance that comes with the migration. But not everyone knows how to correctly configure cloud infrastructure.

“We’re going to see a lot of big hacks based on big cloud providers. And once the forensic analysis is done, they will say yes, they had a machine that wasn’t fully configured. And through that machine, they managed to access all the critical data from the customers.”


2022 Cybersecurity Strategies

However, at the end of the day, cybercriminals want money, and they’ll always choose the option that offers the maximum reward with the minimum investment. As such, while technology and strategies to tailor attacks exist, traditional spray-and-pray attacks will likely continue in 2022.

“When you’re just looking for profit, mass distribution is still very profitable,” Cosoi says. “Maybe they will work in parallel in 2022 and the next years.

“In this underground ecosystem, there will always be groups that are going to make money through the classical ways. They don’t want to invest in levelling up their skills. If there’s good money there, why put it away?”

With the upswing in ransomware and other cyberattacks unlikely to abate in 2022, how can organisations and cybersecurity staff best protect themselves? In a more digitised world, updated strategies are needed.

While there is ultimately no such thing as a perfect security solution, the best strategy is always about raising the price of an attack for the hackers. If the cost of getting your data or money is greater than the reward, threat actors will look elsewhere.

“You need to have security solutions for the entire attack surface. It’s going to be server side, it’s going to be website, it’s going to include segregation of the network. You have to invest in security and look at all the potential gaps that you have.

“Second, you need to train or educate your employees in the security industry. They don’t need to be experts in security. They just need to pay attention to what they’re doing.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.

To subscribe, click here.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data