Worldwide spending on information security products and services is expected to reach more than $114 billion (£88 billion) in 2018 – a 12.4% increase from last year, according to the latest Gartner forecast. In 2019, the market is forecast to grow 8.7% to $124 billion (£95.5 billion).
On the face of it, for companies’ security and customers’ peace of mind, this seems like tremendous news. But all is not as rosy as it may seem.
According to Ian Thornton-Trump, head of cyber security for AmTrust International – a subsidiary of AmTrust Financial Services Inc. (AFSI) – the current dystopian cyber-crime landscape paints a very dismal picture of the effectiveness of that spending.
It’s been predicted that cybercrime will cost the world $6 trillion (£4.6 trillion) annually by 2021 – up from $3 trillion (£2.3 trillion) in 2015. There will be 3.5 million cybersecurity job openings by 2021, and there will be more than 26 billion global IP networked devices or connections by 2020 (up from 16.3 billion in 2015).
Thornton-Trump says: “Despite the increase in cyber security spending, cyber criminals will double their take from company revenue in two years. There will be a huge shortage of cyber defenders and the attack surface the bad guys have to work with will add another 10 billion devices. When vendors remark their product is evolving to meet the threats of tomorrow, I would counter with ‘Not. Fast. Enough’.”
All is not lost, though, and a glimmer of hope for cybersecurity comes in the form of a security revolution and a new metaphorical reign of terror against ‘on premises and hybrid IT’, as Thornton-Trump puts it.
More than 90% of computing instances and workloads will be processed by cloud data centres by 2021, according to Cisco’s predictions; while 6% will be processed by traditional data centres.
If these predictions come to fruition, then building your own data centre may not be the best of ideas.
Cisco also expects that 75% of the total cloud workloads and computing instances will be Software-as-a-Service (SaaS) – up from 71% in 2016.
Slow death
“The slow death of client-server on premise applications continues to linger,” Thornton-Trump explains.
“So, if most of the IT systems will be found in cloud data centres by 2021, the security revolution in tools and training has to be applied to securing those cloud data centre hosted systems. The endpoint defence-in-depth or layered security model is still relevant, but the investment in those layers needs to change; with most of those systems located in the cloud and as SaaS offerings, credential management along with multi-factor authentication becomes the most important layer.”
This is something that Thornton-Trump feels very few companies are doing today, mostly due to legacy systems.
“It’s no wonder that cyber criminals keep pillaging them,” he says. “There’s an unexpected ally in user account management in SaaS – the accounting department. In the SaaS monthly billing model or pay-as-you-go billing, the question will be near constant: ‘Can we shut that account down to save money?’ Look for accounting to become the ‘Committee of Account Safety’ and be wary of their budget guillotine.”
The prediction of where IT systems will be located by 2021 gives us an idea of where the data in those systems will be found – the cloud data centre.
He predicts that “as we move towards an environment where endpoints connect to SaaS and SaaS systems talk to each other using APIs, it becomes increasingly necessary to secure access to those systems with strong credential management with less important on the hygiene of the endpoint.
“Credential-stealing payloads and even ransomware payloads become less impactful when no important data is found on an endpoint and it can’t be accessed because of multi-factor authentication protections.”
The future of business IT can be found in moving business applications and data into cloud-hosted services – as quickly as possible – and reducing exposure of any data in an unencrypted format on any endpoint, Thornton-Trump suggests.
“With robust credential management in place,” he comments, “the detection of a compromised endpoint becomes easy – failed login due to multifactor account protection alerts – and the impact of that compromised endpoint from a compliance perspective becomes minimal.”
No data on the endpoint equates to no unauthorised data disclosure and restricts the ability to encrypt devastating ransomware.
He explains: “From the IT management perspective, imagine if the build you have stops at the web browser of the user’s choice, completely platform-agnostic with all the applications the user needs found as webservices.”
Access and provisioning are controlled by the user’s manager through a console, and one of the only large expenditures in security is on the multi-factor authentication and VPN solution for mobile workers. Vulnerability management on the endpoint, as well as anti-malware defences, are still required for compliance, says Thornton-Trump, but the impact of a security breach will be significantly decreased and confined.
So, how close are we to this security utopia? That would depend on who you ask. Around 56% of C-level executives believe that that their organisations have migrated workloads to the cloud. Yet 35% of IT directors believe the same, with 53% of companies apparently committed to a hybrid approach – a combination of on-premise and cloud.
Thornton-Trump concedes that there is still work to do, highlighting that “It appears we are only halfway there, and for those companies that are not moving to the cloud with all due haste, their security posture may be living on a prayer.”
Nonetheless, he remains optimistic about the future of cyber security, but thinks a massive re-alignment of InfoSec spend is looming on the horizon.
He says: “The situation most business find themselves in – hybrid IT – or, as I like to call it the ugly place in between maintaining on-premises legacy and moving to fully cloud-hosted – is not sustainable. We have never been more vulnerable than right now, and hybrid IT has massively increased the attack surface and reduced the effectiveness of antiquated layered defence strategies.
“What does remain the same? The attackers. It’s not surprising to me evolution of your business to hosted services will demand revolution from vendors and security professionals.”
Ian Thornton-Trump will delve further into this topic, sharing his vast insights, during his ‘Security Revolution’ talk at DIGITExpo on 14th November at the Edinburgh International Conference Centre. Book your free place here






