THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Wednesday, December 28, 2022
Google’s (NASDAQ: GOOGL) cybersecurity predictions for 2023 anticipate that this malicious economy will only continue to expand and diversify.
FREMONT, CA: According to the FBI, cybercrime costs USD 6.9 billion annually. According to Google's (NASDAQ: GOOGL) cybersecurity projections for 2023, this criminal economy will only grow and diversify.
Predictions include an increase in ransomware and insider risk, cybercrime vendors adapting to new business models, and, fortunately, a wider deployment of passkeys technology. Continue reading to learn more about them.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Identity and Authentication Attacks will Remain a Constant Threat: Organisations will still face challenges from identity- and authentication-related threats, where relatively inexperienced threat actors can buy credentials on the black market or deceive their way inside an organisation. Platform developers will face pressure to assist customers and businesses in thwarting malware that grabs their credentials.
Insider Risk Will Increase as Threat Actors Target Trusted Employees: Insider dangers will rise as attackers try to extort and compel otherwise reliable insiders into doing bad things. In the meantime, attacks on federated identity and authentication manufacturers will intensify in an effort to hit additional software-as-a-service (SaaS) providers. People will also start to comprehend the Y2K-scale degree of labour necessary in moving to post-quantum cryptography.
Ransomware Attacks on Public and Private Sectors Will Continue to Increase: The prevalence and expansion of ransomware attacks in both the public and private sectors will continue to increase globally. Industry-specific threats and capabilities will expand over the broader attack surface, impacting verticals like healthcare, energy, finance, and more.
Broader Adoption of Passkeys Technology:The world will see widespread passkey usage from developers and users, as well as in standard security jargon, in addition to password management and account security enhancements. Websites and applications will be more likely to implement passkeys for both consumer-facing and internal admin tools since SMS/one-time password (OTP) phishing is expected to increase.
The browser will become an even more significant asset for enterprise security in a hybrid corporate environment and as more work is done online.
The need for cybersecurity expertise and competence at all organisational levels in the public and private sectors will continue to outpace the pool of available personnel. This will highlight the necessity for future investments in the development of multidisciplinary cybersecurity capabilities.
Cybercrime Vendors Will Shift their Business Models: Both IT corporations and governments will exert more pressure on commercial spyware vendors and operators of hacking operations. But rather than disappearing, these threat actors will change their organisational structures, names, and economic models. Campaign and election security, particularly discussions about information operations (IO), will be front-and-centre problems as the 2024 election campaigns get underway.
Cybercriminals Will Look to Target Reused Passwords and Secret Question Fields: With numerous data breach dumps floating around on the dark web, there will be an increase in assaults utilising not only previously used passwords but also all of the secret question sections (birthdate, SSN, street addresses or others).
With the added bonus that these mechanisms are also simpler and more user-friendly, apps and websites will increasingly embrace secure authentication, such as federated identities and passkeys, in place of login, password, SMS code, and other methods, in order to protect themselves.
More in News