But what’s the ‘main thing’ when navigating technology as we enter 2020?
The simple answer is… Cybersecurity.
As innovation explodes into every area of our lives, cybersecurity is providing the glue that can enable the good and disable the bad for implementing cutting-edge innovation as well as reducing risk from older vulnerabilities. We also see cybersecurity continue as the top priority for chief information officers (CIOs) in 2020, just as it has been for most of the past decade, with groups like the National Association of State CIOs (NASCIO).
But even as cybersecurity solutions offer a way forward to ensure privacy protections are workable and effective, most people see the data breaches, ransomware, identity theft, denial-of-service attacks and other cyberattacks as proof that cybersecurity has become the Achilles Heel, not the savior, for new innovation. Even as exciting advances occur in artificial intelligence (AI), autonomous vehicles, 5G networks cloud computing, mobile devices and the Internet of Things (IoT), these same developments seem to cause negative societal disruptions that make daily news headlines.
So what will happen next with cybersecurity? That’s what this annual security prediction roundup will cover, from the perspective of the top cybersecurity industry companies, thought leaders, executives and journalists. Every year we catalogue the evaluators to see who has made a New Year’s security prediction list and checked it twice.
And the best security industry prediction reports do much more than just make educated guesses at what might happen in the future. The top 20 security predictions for 2020 dig deep into global security incident databases, analyze what’s working and what’s not, examine new cyber solutions and use science and data to gaze into the future.
The best prediction research shows us the “who, what, when, where and how” about the cybersecurity statements made. Some forecasts even include the why — with the best offering detailed context and a wider story that crosses years and sometimes even decades and learning from history. These presentations offer their materials in professional ways to maximize end-user usefulness regarding potential answers and recommended actions for enterprises and individuals to take.
Some call them security predictions, while others refer to them as cybersecurity trends. Several researchers prefer to offer “cybersecurity forecasts,” while others refer to “growing trends” or “situational outcomes” — based upon connecting the incident dots or running various data breach scenarios. Regardless, the central questions are very similar and methodologies used are (generally) repeatable.
2020 — and the New Decade
What are the greatest threats for the coming year? What solutions will be most important? What data breaches or ransomware attacks or other threats will cause the most harm? And readers say: "The more detail the better — please."
Common prediction themes across vendors include the 2020 elections in the U.S., more targeted ransomware, more ways to attack the cloud, and an explosion of problems with deepfake technology.
There’s disagreement on the most important cyberthreats to focus on as we head into 2020, even though everyone agrees that cybersecurity is more important than ever before. Just as in 2019, we have the continuation of arguments for and against AI (i.e., how helpful is AI really and will our enemies use it or not?). Also, the continued disagreement on whether cloud versus mobile threats are more of a challenge.
For 2020, AI does show up again in a number of new ways — with several specific warnings for those who fail to use AI to counter bad actors who will be using it.
There are also many ways that you and your organization can benefit by studying these predictions and implementing recommendations, and we outline several of those career benefits here. As always, I encourage you to visit the full reports, blogs, articles, PDFs, videos, and other materials referenced (hyperlinked) to dig deeper into the details on each company prediction list.
Please note that the embedded videos are only a small part of the marketing of these wider prediction reports. I also encourage readers to review the award winners for 2020 predictions at the end of this post.
Quick Security Prediction Recap on the Teen Years within the 21st Century
I’ve been writing about security predictions for more than a decade, and this annual holiday season tradition is now exploding even faster than the overall cybersecurity industry — mainly because cyberprotections are showing up as a top priority in every other industry from finance to defense and from government elections to toys. And make no mistake, this topic carries much more weight now than in December 2009, when we were heading into the second decade of the 21st century.
As I wrote back in 2016, while some were predicting that the cybersecurity industry would diminish in importance and be automatically built into every technology product (and quietly protect us from behind the scenes), the opposite has happened. Cybersecurity predictions, and the information security market overall, continue to surge as we head into 2020. Here’s what I wrote four years ago:
“The more the security and technology industries grow, the more predictions we will have. From the Internet of Things, to new technologies to robots to self-driving cars, do you really think we will be talking about security and privacy less in 2020? I don’t.
Predictions are not new, and they are not going away. In fact, they are just getting started. Congratulations security industry, and welcome to center ring in this three-ring circus. Yes, it is a very big circus, but that’s where all the action is.”
This year has brought (by almost double) the largest and most diverse number of security predictions ever online — when measured by several metrics. I received literally hundreds of emails and thousands of individual predictions — and also went out to explore as much of “the rest” online as of mid-December 2019. If we missed you or you want to add a prediction, email me at the https://www.govtech.com/blogs/lohrmann-on-cybersecurity/ contact address listed, and you may get a mention near the end — with a link to your list of your 2020 cyber insights. Our goal is to be as comprehensive as possible with this forecast summary and be a one-stop shop for security prediction lists for 2020.
As a reminder, here are the prediction reports from the past three years for your review and to help keep score:
The Top 19 Security Predictions for 2019
The Top 18 Security Predictions for 2018
The Top 17 Security Predictions for 2017
The Top 20 Security Predictions Reports by Security Industry Company
1) Trend Micro – We lead off with another WOW prediction-report from Trend Micro – which takes the top vendor prize for best prediction report for the third year in a row. (And it wasn’t a close call.)
Here’s the Trend Micro intro: “The year 2020 marks the transition to a new decade, and recent notable events and trends signify a similar changeover in the threat landscape. Cybersecurity in 2020 and beyond will have to be viewed through many lenses — from differing attacker motivations and cybercriminal arsenal to advancing technological developments and global threat intelligence — only so defenders can keep up with and anticipate cybercrime mainstays, game changers, and new players. …”
A visit to: The New Norm: Trend Micro Security Predictions for 2020 will quickly show you the thought-provoking, creative, expert research and packaging that sets this report apart. Trend Micro groups their detailed predictions into 4 sub-headings (with explanations under each prediction) about our cybersecurity future, including:
Complex (these are only small excerpts):
- Attackers will outpace incomplete and hurried patches.
- Cybercriminals will turn to blockchain platforms for their transactions in the underground.
- Banking systems will be in the crosshairs with open banking and ATM malware.
- Deepfakes will be the next frontier for enterprise fraud.
- Cybercriminals will home in on IoT devices for espionage and extortion.
- Critical infrastructures will be plagued by more attacks and production downtimes.
- Vulnerabilities in container components will be top security concerns for DevOps teams.
- Serverless platforms will introduce an attack surface for misconfiguration and vulnerable codes.
- User misconfigurations and unsecure third-party involvement will compound risks in cloud platforms.
- Predictive and behavioral detection will be crucial against persistent and fileless threats.
- Threat intelligence will need to be augmented with security analytics expertise for protection across security layers.
2) FireEye - FireEye once again provides an excellent special report (20-pages) with predictions and guidance from four of their top leaders.
For 2020 the FireEye Report is entitled, The Road Ahead: Cyber Security in 2020 and Beyond. They include some insightful video from their top leaders and offer interesting perspectives from different vantage points in their organization. (However, I missed the opening letter from CEO Kevin Mandia that we saw last year, along with solid overall company predictions. See Kevin's video interview below.) For example, here are insights from Sandra Joyce, Senior Vice President of Global Intelligence:
- Big Picture – We are all targets. (If you work with a high value target, you are also a high-value target.)
- Ransomware Tactics Evolving - In 2020, defenders need to be looking out for new techniques involving ransomware. What we’ve been seeing in the underground is threat actors advertising their access to organizations, no matter what industry, and trying to find partners who have ransomware that they can deploy deep in those networks in a very customized fashion. We’ve also seen some of the most sophisticated criminal intrusion operations shift to this type of ransomware deployment, away from other tactics.
In 2020 there will be a broadening push on providers to offer more proof of compliance to industry regulations and customer requirements, with clear ways for their customers to validate that vendors are doing what they say they are doing.
Overall, the FireEye's prediction report addresses these topics:
- How increasing use of the cloud continues to change security
- The skills gap and thinking outside the box when it comes to staffing
- Threats such as ransomware and weak spots such as supply chain
- Cyber activity during the upcoming U.S. elections
- How organizations and vendors need to start thinking about security
- The emerging role of the general counsel
- The continued evolution of information operations
- Geopolitics as a driver of cyber activity
- Increasingly sophisticated cyber criminal operations
3) WatchGuard Technologies again released a top-notch set of new year predictions. These cover the most prominent attacks and infosec trends that the WatchGuard’s Threat Lab research team believes will emerge in 2020, including voter registration database attacks, state-level GDPR legislation, cloud-focused ransomware, and more.
WatchGuard’s named their report: “A Simplified Approach to staying secure in 2020,” which is in contrast to the Trend Micro approach regarding complexity. What sets them apart (again) is the helpful video content to support each prediction, which is very professionally delivered.
Here are WatchGuard’s main predictions:
- Ransomware Targets the Cloud
- GDPR Comes to the USA
- Voter Registration Systems Targeted During 2020 Elections
- The CyberSecurity Skills Gap Widens
- During 2020, 25% of All Breaches Will Happen Outside the Perimeter
- Attackers Will Find New Vulnerabilities in 5G / WiFi Handover
- Multi-Factor Authentication (MFA) Will Become Standard For Midsized Companies
4) Forcepoint offers this excellent report: 2020 Forcepoint Cybersecurity Predictions and Trends, which includes video commentary on each prediction. They cover similar election and ransomware issues as others, but I especially like their unique prediction for “Deepfakes-as-a-Service.”
Deepfakes was a term that was coined in 2017 and relates to fake videos being created by deep learning techniques. We expect deepfakes to make a notable impact across all aspects of our lives in 2020 as their realism and potential increases. Our prediction is fourfold:
- Ransomware authors will send targeted deepfakes to ransomware targets. Recipients will see realistic videos of themselves in compromising situations and will likely pay the ransom demand in order to avoid the threat of the video being released into the public domain.
- It is well known that Business Email Compromise/Business Email Spoofing has cost businesses billions of dollars as employees fall for the scams and send funds to accounts in control of cybercriminals. In 2020 deepfakes will be used to add a further degree of realism to the request to transfer money.
- We have already seen deepfakes in the political arena in 2019. With the 2020 United States presidential elections due in November 2020 we expect deepfakes to be leveraged as a tool to attempt to discredit candidates and push inaccurate political messages to voters via social media.
- We will see Deepfakes As A Service move to the fore in 2020 as deepfakes become widely adopted for both fun and malicious reasons.
- 5G offers unprecedented data theft speeds
- Organizations will become “Cloud Smart” but remain “Cloud Dumb”
- Organizations will mature in their approach to data/privacy protection legislation
- Cybersecurity strategies will incorporate a move from Indicators of Compromise to Indicators of Behavior
5) McAfee - McAfee Labs 2020 Threats Predictions Report was once again a top-notch forecast report which shows their quality research and insightful approach offered. This report is a glorified blog post, but with helpful links to their tops predictions, including:
- Broader Deepfakes Capabilities for Less-Skilled Threat Actors
- Adversaries to Generate Deepfakes to Bypass Facial Recognition
- Ransomware Attacks to Morph into Two-Stage Extortion Campaigns
- Application Programming Interfaces (API) Will be Exposed as The Weakest Link Leading to Cloud-Native Threats
- DevSecOps Will Rise to Prominence as Growth in Containerized Workloads Causes Security Controls to ‘Shift Left’
- More Awareness, More Regulations
- New Tricks for the New Year
- Dark Web Draws in More Data
Splunk broke their predictions down into categories like:
Social Engineering
- Deepfakes will uplevel the danger of social engineering. New ways to lie make it more imperative to instill a strong security culture.
- Cyber attacks will hit home (literally). Hackers and nation-state attackers are targeting systems that run our day-to-day lives, and they’re already succeeding. It’ll only get worse in an election year.
- Hackers will find new low-hanging fruit in the cloud. The most advanced (and potentially devastating) cloud attacks will occur at machine speed in 2020.
- MITRE ATT&CK will become the go-to framework and common vocabulary for every SOC. The real-world knowledge base has made tremendous gains in security circles, and deservedly so.
7) Kaspersky Labs – Kaspersky always produces a ton of great material regarding threats for the coming year, threat reports, detailed analysis of risks, and so much more from all over the world. The problem (and reason they are not higher on this list) is that it is hard to find and very segmented and targeted towards many different audiences. While this may be a deliberate marketing tool that works for them around the world (and they are much bigger outside the USA), it is tough to find one solid list of all their predictions.
The good news, is that I have pulled from several lists and provide links here.
To begin, visit Kaspersky’s report: “Advanced Persistent Threats in 2020: abuse of personal information and more sophisticated attacks are coming.” Here are their headline items (with details at the links, as always):
- The abuse of personal information: from deep fakes to DNA leaks
- False flag attacks reach a whole new level. Explanation: This will develop further, with threat actors seeking not only to avoid attribution but also to actively lay the blame on someone else. Commodity malware, scripts, publicly available security tools or administrator software, mixed with a couple of false flags, where security researchers are hungry for any small clue, might be enough to divert authorship to someone else.
- Ransomware shifts toward targeted threats.
- New banking regulations in EU open new attack vectors.
- More infrastructure attacks and attacks against non-PC targets.
- Cyber-attacks focus on trade routes between Asia and Europe.
- New interception capabilities and data exfiltration methods.
- Mobile APTs develop faster.
- Personal information abuse grows, armed with AI.
- IT security economics in 2019
- Financial threat predictions in 2020: fintech, mobile banking and e-commerce to intensify
- Ready Or Not… Balancing Future Opportunities With Future Risks.
- Biometric Risks
- How will the cybersecurity industry evolve in 2020?
8) Sophos really stepped up their game this year with this Sophos Labs 2020 Threat Report. Just a well-done, solid material with plenty to offer – and excellent lead-in exec summaries here. They even take a 10-year-out prediction with a bold: “Ten years out, machine learning targets our ‘wetware.’”
Top Sophos predictions (with detailed analysis on each item) include:
- Ransomware attackers raise the stakes
- Mobile malware trends: Dirty tricks are lucrative, Ad money feeds non-malicious scammers, Fleeceware charges consumers hundreds, Bank-credential stealers evade Play Store controls, Hidden Adware.
- The growing risks of ignoring "internet background radiation" - Remote Desktop Protocol in the crosshairs, Public-facing services targeted by increasingly sophisticated automation, Why Wannacry may never totally disappear, and why you should care.
- Cloud security: Little missteps lead to big breaches - The biggest problem in the cloud is the cloud itself. Misconfiguration drives the majority of incidents. Lack of visibility further obfuscates situational awareness. A hypothetical cloud security breach incident.
Global cyber-security predictions for 2020:
- A new cyber ‘cold war’ – The new cold war is intensifying, and taking place online as Western and Eastern powers increasingly separate their technologies and intelligence. The ongoing trade war between the U.S. and China and the decoupling of the two huge economies, is a clear sign. Cyber-attacks will increasingly be used as proxy conflicts between smaller countries, funded and enabled by large nations looking to consolidate and extend their spheres of influence, as seen in the recent cyber operations against Iran, following attacks on Saudi Arabia’s oil facilities.
- Fake news 2.0 at the U.S. 2020 elections
- Cyber-attacks on utilities and critical infrastructures will continue to grow
- Targeted ransomware
- Phishing attacks go beyond email
- Mobile malware attacks step up
10) RSA Security (A Division of Dell) - RSA offers this easy to find and very well done report (that is very easy to use and jump around) with 20 Predictions for 2020: Preparing for the Future of Digital Risk.
They cover Business Predictions, InfoSec Predictions, Technology Predictions, Cyber Predictions, Consumer Predictions and Regulatory Predictions. While we liked RSA’s graphics and great displays, the predictions seemed a more like trends than new happenings. Still, definitely worth reviewing this report.
Here are their top 5 Predictions:
- The rise of the cyber-savvy board
- Authentication demands adapt to evolving needs
- A focus on data sovereignty in the Middle East
- Brexit brings new risk assessments
- Security shifts left - Increasing demand for cloud-native apps will force security teams to work more closely with DevOps. Moving pen-testing and code analysis up in the development lifecycle will boost product security.
11) AT&T - AT&T ThreatTraq came out with This Video With Predictions and Thoughtful Commentary. What I like about this is the relaxed, expert commentary which explains these three predictions in detail in a comfortable setting via a conversation.
- AT&T led with Artificial Intelligence (AI) – Machine Learning (ML) being used in documented cyberattacks – or at least used more in the background.
- Second, Malware Will Take Advantage of Domain Fronting
- Third, IoT Security getting better.
12) Beyond Trust has a solid list of security predictions, that also go deeper into the 2020s (to 2025) with this lead in quote: “The more CISOs and other IT staff understand the security implications of evolving technologies, the better prepared they are to make the right investments for their business,” said Morey Haber, CTO and CISO at BeyondTrust.
Here are a few highlights for 2020:
- Malware Auto-Updates Increase – Since many applications auto-update, cyber criminals now target cloud-based update mechanisms using a variety of techniques. Most users trust their applications to auto-update and may be unaware of the threats made possible by a compromised cloud connection. Although old-school software piracy is on the decline due to the cloud, cyber criminals’ creativity will continue to zone in on auto-updates to infect users. Expect high profile applications and operating systems to be targeted by these advanced threats in 2020.
- Reruns of Old CVE’s
- Identities Become the Latest Attack Vector
- End User Passwords Phase Out – Operating systems and applications will continue to push to end dependency on
- Next-Gen Processors Gain Footing
- Facial Recognition Transactions Increase
- Cloud Offerings Triple
13) Fortinet offers this solid list of industry trends and New Threat Predictions for 2020. This very good report also offers a complementary set of activities in their threat landscape report. According to Derek Manky, chief, security insights & global threat alliances at Fortinet, "Much of the success of cyber adversaries has been due to the ability to take advantage of the expanding attack surface and the resulting security gaps due to digital transformation. Most recently, their attack methodologies have become more sophisticated by integrating the precursors of AI and swarm technology. Luckily, this trajectory is about to shift, if more organizations use the same sorts of strategies to defend their networks that criminals are using to target them. This requires a unified approach that is broad, integrated, and automated to enable protection and visibility across network segments as well as various edges, from IoT to dynamic-clouds.”
Topping their list of Fortinet predictions for 2020 are these items:
- Combining machine learning with statistical analysis to Predict Attacks by uncovering the underlying attack patterns of cybercriminals, thereby enabling an AI system to predict an attacker's next move, forecast where the next attack is likely to occur, and even determine which threat actors are the most likely culprits.
- A deep look at how Deception Technologies can be used to create a virtually insurmountable layer of defense around your network, regardless of how far it has been distributed.
- Recent developments in Law Enforcement that will enable them get out ahead of cybercrime.
- And the rise of New Zero-Day Exploits that, when combined with AI-enabled systems, will enable cybercriminals to strike in ways and places that many organizations are simply unprepared to defend.
14) Experian – Offers another good report entitled: Data Breach Industry Forecast 2020 – which is free, but requires registration. You can read some more details on their report at this NextGov article.
Experian’s main findings forecasts include (with detailed explanation in the report:
- Cybercriminals will leverage text-based “smishing” identity theft techniques to target consumers participating in online communities, such as those supporting presidential candidates, with fraudulent messages disguised as fundraising initiatives.
- As cities install more free public Wi-Fi systems hackers will take to the skies via the use of readily available drones to steal consumer data from devices connected to unsecure networks on the streets below.
- Cybercriminals will use so-called “deepfake” video and audio technology to disrupt the operations of large commercial enterprises, and potentially create geo-political confusion among nation states, in addition to disruption in financial markets.
- As a form of protest, we will see many burgeoning industries, such as cannabis retailers, cryptocurrency entities, and even some environmental organizations, targeted for cyberattacks as a result of online activism or “hacktivism.”
- With mobile payment options popping up everywhere from a local café to the beer vendor at a stadium, we predict that there will be a significant spike in identity theft as cyber criminals seek to exploit the convenience of point-of-sale transactions, especially at large venues like concert festivals and sporting events.
15) Gartner - Gartner Top Strategic Predictions for 2020 and Beyond – Garter always does an excellent job of offering predictions on technology risk and cybersecurity in detailed ways – the trouble is that most of their material must be purchased. This fact lowers their ranking each year; nevertheless, the offer very helpful, specific advice that is oftentimes unique. Three of Gartner’s free prediction lists that I found intriguing as we head into 2020 include:
Gartner Top Strategic Predictions for 2020 and Beyond – including these three excerpts:
- BYOD becomes BYOE - Through 2023, 30% of IT organizations will extend BYOD policies with “bring your own enhancement” (BYOE) to address augmented humans in the workforce.
- Mobile cryptocurrency increases - By 2025, 50% of people with a smartphone but without a bank account will use a mobile-accessible cryptocurrency account.
- Blockchain authenticates content - By 2023, up to 30% of world news and video content will be authenticated as real by blockchain, countering deep fake technology.
- 99 per cent of threats to data security will spring from underlying vulnerabilities already known to the enterprise and its workforce.
- About 40 per cent of the organizations dealing with DevOps will purchase developed applications.
- Cloud-based access security brokers or CASBs should take note because, by 2020, 80 per cent of new deals will collaborate with a truckload of security features.
16) Forrester – Like their rival Gartner, Forrester also offers lots of excellent predictions in many business areas – but generally these come at a cost as in the case of their cybersecurity report for 2020. (Side note: I don’t review prediction reports that cost you money, but I will review reports that require users to complete a form to download.)
Nevertheless, there are exceptions, such as this Forrester Predictions 2020: On The Precipice Of Far-Reaching Change, which available for download once you provide contact your details.
Here are two highlights from that guide:
- Deepfakes will cost businesses over a quarter of a billion dollars.
- Privacy class-action lawsuits will increase by 300%.
17) Forbes – Gil Press always does a nice job compiling diverse cybersecurity predictions over at Forbes, and this year is no exception. Last year he had 60 predictions for 2019 from various sources, and this year he is up to a robust 141 security predictions that are all over the map – but worth reading.
Here are his first two with great sources throughout:
- “AI is going to be HUGE in 2020. And by huge, I mean that a lot of vendors will claim they are using AI—ranging from using simple linear regressions, up through using deep learning. While linear regression is pretty far from AI, we might trust those vendors more to deliver a working product than many who use deep learning techniques as the entirety of their solution. What we’ll see in many spaces is folks starting to understand the limitations of algorithmic solutions, especially where those create, amplify, or ossify bias in the world; and companies buying technologies will really need to start understanding how that bias impacts their operations”—Andy Ellis, Chief Security Officer, Akama
- “As AI adoption in cybersecurity expands, security concerns around AI bias will grow. As security teams' use of AI continues to grow, they'll need to monitor and manage for potential bias in their AI models to avoid security blind spots that result in missed threats or more false positives. One way to help prevent bias within AI is to establish cognitive diversity - diversity in the computer scientists developing the AI model, the data feeding it, and the security teams influencing it"—Aarti Borkar, Vice President, IBM Security
Tech Trends 2020: Moving From Disruption To Transformation – Here’s one item from this list:
- Cybersecurity: Fear Of The Cloud - 2020 will be the year of cloud security anxiety. According to a survey conducted by Cyber Security Hub, 85% of executives view it as one of their largest cybersecurity threats. Though AWS, Azure and Google have worked hard to bring down costs and increase security measures, vast data storage will always be vulnerable to attack, and these attacks continue to grow in quantity and quality.
And here’s a late update. Gil Press just released another 42 more cybersecurity predictions from industry executives for 2020. This just reaffirms what I mentioned above and continue to see in December 2019 – namely that everyone wants to get into the security prediction business.
18) Imperva – Imperva Offers their Top 5 Cybersecurity Trends to Prepare for in 2020 This well-written blog starts with: “I don’t need a crystal ball to predict that in 2020 cybersecurity attacks will accelerate and the tactics will evolve. We’ll continue to be hounded by greater volumes of the attacks that have threatened us for years and, as businesses adopt new innovations, new vulnerabilities to threats will surface.”
Here are Imperva’s Top 4 Trends (with details at the link):
- Cloud Transformation Will Accelerate
- Automated Attacks Will Increase
- Businesses Will Adopt Zero Trust
- Non-Compliance Will Become Costly
19) Bitdefender – Bitdefender once again offers their 2020 Cybersecurity Predictions via their company’s Business Insights Blog. Jumping right in, the list looks fairly familiar with a few new twists:
- More vulnerabilities with greater impact
- Complexity of software and knowledge needed for attacks and protection will increase. Malware sophistication grows
- Increased diversification of IoT without proper security: attacks on infrastructures and reruns of old CVEs
- State actors will increasingly use cyber-warfare, at least covertly. Attribution to other nations
- Fight against government censorship (fight for privacy) will increase
20) Thycotic – Rounding-out the top 20 industry cybersecurity prediction reports is an intriguing from my respected colleague Joseph Carson at Thycotic, who always brings new material and unique insights to online webinar panels and cyber conference speeches. Thycotic’s Cyber Security Predictions and Trends for 2020
- Deepfakes will take Identity Theft to a new level
- We’ll move beyond Zero Trust into Building Trust, with PAM still a CISO priority
- Prediction: Biometrics will not be used for Security but more as an Identifier
- Prediction: Privileged Access will become critical to securing IoT
- Prediction: The 6th Day will move closer to becoming reality
So what about all of the other cybersecurity predictions out there, along with hundreds of small tech companies with predictions from their CEOs? Here are some of those, but I also encourage you to visit the Forbes lists above which has even more.
- HackerNews.com – Top 5 Cybersecurity and Cybercrime Predictions for 2020
- Bitglass - Bitglass 2020 Predictions: M&A, Data Privacy, Sophisticated Attacks and Misconfigurations -- Oh My!
- DivvyCloud - Cybersecurity and Data Privacy Trends in 2020 by Chris DeRamus, CTO and co-founder – 5 listed, here’s one:
Prediction Excerpt:
Drones Open up New Pathway for Intelligence Gathering - To date, the security concern around drones has mostly been focused on the physical damage nefarious actors, including nation states, could perpetrate. In 2020, we could start seeing attackers focus more on what drones know and how that information can be exploited for intelligence gathering, corporate espionage and more.
- Valimail - Peter Goldstein, CTO and co-founder offers his 2020 Predictions for message identification, email security, AI and more
Email security will prove to be the weakest link in election security. Email is implicated in more than 90 percent of all cybersecurity attacks, and election infrastructure is also vulnerable to email-based attacks. This means email security must be a priority for thwarting interference with the 2020 presidential election. But research shows the majority of U.S. states are overlooking this vulnerability. Only 5% of email domains associated with local election officials across the U.S. have implemented and enforced DMARC.
- SecPlicity: Offers this piece which focuses on how the cybersecurity skillset gap will widen – while pointing to Watchguard’s video on the topic.
- Cybereason - CSO Sam Curry offers his thought-provoking analysis in 2020 Cyber Crystal Ball: Extending From 2019 (part 1 of 4), Part 2: The Adversary, Part 3: The 2020 Security Industry and Part 4: The Hope for 2020 – all published in in Forbes.
- Radware - Radware offers these 2020 predictions which bring up some new topics – like Quantum Computing.
Quantum communication, the field of applied quantum physics for protecting information channels against eavesdropping, will become an important technology for organizations that trade in sensitive and highly valuable information. …
But as researchers get closer to quantum supremacy, the tension will grow among organizations that are handling sensitive and highly valuable information. This tension will push certain organizations across the line to take protect their communications against cryptographic attacks through quantum communication technology. I predict that we will see this trend begin in 2020.
- Exabeam – Exabeam offers Eight Cybersecurity Predictions for 2020
- Claroty - Dave Weinstein, CSO of Claroty and former CTO of New Jersey, has some predictions for where he sees the state of industrial cybersecurity, critical infrastructure and the role of IT and OT security professionals going in the coming year. Dave’s prediction are here.
- BairesDev - Paul Azorin, Founder and Chief Technology Officer, BairesDev, offers his Cybersecurity & data privacy trends in 2020
As a result, global investments in information security are expected to total more than $124 billion in 2019.
What’s more - companies are currently spending between $1,300 to $3,000 per employee on cybersecurity. This averages to about $2,300 per employee for most businesses. This, however, is not nearly enough. That’s why corporations are expected to increase information security spending by 8.7 per cent per year.
Excerpt: The smallpox of cybersecurity - passwords - will be eradicated by 2025. Passwords are ingrained in our society because they've been around for over 60 years, but this doesn't mean it's the safest way to secure our digital lives. Passwords are not only a hassle - they're antiquated and open us up to even more cyber threats. Similar to how smallpox was eradicated, if we ban together, we can wipe out passwords and the onus is on the technology industry to drive security forward by eliminating them. Capabilities like zero sign-on, software and hardware tokens, behavioral analysis, and biometrics already exist that allow organizations to switch to passwordless authentication today.
- Bugcrowd - Casey Ellis, chairman, founder and CTO of Bugcrowd offers his 2020 Vision: Cybersecurity predictions for the year and beyond – I really like Casey’s perspectives and enjoy listening to him speak at events. I was on a panel with him in Detroit in 2016, and respect his global cyber expertise.
When protecting against known elements, such as WannaCry or other pre-existing threats, organizations have a clear picture of what the enemy looks like and can thereby adopt successful defensive techniques against such known threats. However, the biggest threats today are the ones we won’t know about until tomorrow (or even later), which is why a proactive, hacker-minded approach is integral to catching these issues before they’re found and exploited in the wild.
The next big breach is already happening now, and we’ll only learn about it months down the road. From what we continue to see with leaks and breaches, it’s often the exposed but unknown attack surface is that’s much more likely to sink an organization than breaks in their core apps or architecture (an exposed file, key, server, that nobody knew about or thought was a risk). And while one fundamentally can’t expect the unexpected, organizations can take steps to ensure there are fewer unknowns. In doing so, reduce their available footprint for being surprised, as well as get ahead of potential back doors to the organization.
- IoT World Today offers these 6 IoT Security Predictions for 2020- As we transition to a new decade, there is growing maturity in the field of IoT security, but also a wave of new risks.
In 2020, the prospect of smart building security is bound to become more of a top-of-mind concern for facility managers. With buildings accounting for eight out of 10 connected things in 2020, according to Gartner, smart buildings could provide new avenues for adversaries to attack. Experts are divided, however, whether there will be a significant uptick in such attacks next year. Mirel Sehic, global director of cybersecurity for Honeywell Building Solutions, expects such an increase. Attackers could use building management systems as a pivot point to get to IT data as well as to manipulate building controls.
- Honeywell – Speaking of Honeywell Building Solutions, Honeywell Predicts 2020’s Top Cybersecurity Trends for Buildings
The need to secure both Operational Technology (OT) and traditional Information Technology (IT) is expected to create demand for a new skillset and new type of security professional.
- BitDam - Liron Barak, CEO, BitDam offers her top 5 cybersecurity predictions for 2020
- Enterprise Irregulars – The online magazine lays out 10 Predictions How AI Will Improve Cybersecurity In 2020 for various vendors. Here’s one from Sean Tierney, Director of Threat Intelligence at Infoblox:
Excerpt: The BYOD and CYOD trend enterprises have adopted will be met with employee pushback as increased regulations and growing privacy concerns continue to raise awareness about inefficient device security:
“67% of employees report using a personal device at work to some degree. As enterprises continue to adopt a BYOD (bring your own device) or a CYOD (choose your own device) strategy for their employees, there will be continued push pack from employees who are required to relinquish control over their mobile devices and the private data stored on them. As the stakes for privacy management become higher and higher from endless breaches (54% higher in 2019 alone) and increased regulations, like GDPR and CCPA, we’ll see enterprises deploy more effective means of privacy control for its employee’s personal devices (like application-specific security, as opposed to only device-level). This will mitigate privacy invasion for employees and enable tighter vulnerability controls for the enterprise, all while still providing necessary corporate data and accessibility to the end-user via the mobile device of their choice.” - John Aisien, CEO of Blue Cedar
Excerpt: Revenue growth is not a simple equation.
CompTIA predicts that the global IT industry will grow by 3.7% this year, and IDC is projecting $5.2 trillion in global revenue. However, this growth is not consistent across all areas of IT. IDC expects that technology services and traditional hardware will each grow by 23%, software will grow by 50%, and emerging technologies will grow by a whopping 104%. This growth in emerging technology is the driver for all the hype, but there are two things to remember. First, solutions using emerging technology require significant investment in skills and product support. Second, emerging technology solutions don’t exist in a silo—they are part of overall architectures that include traditional components such as networking or storage. Those components often need to be upgraded to take advantage of new trends, so there are revenue opportunities across the board, but simply targeting emerging technology will not automatically lead to astronomical growth.
Also from CompTIA: The biggest customer needs are (and will be) around software development and cybersecurity.
- Varonis – This Forbes article brings some unique predictions like this one Brian Vecci, Field CTO, Varonis:
- Jumino – Offers these predictions on Biometrics and identity verification.
The global market for mobile biometrics is forecast to grow at an impressive 31.14 percent CAGR, adding $28.45 billion per year in incremental growth between 2018 and 2023, despite the CAGR decelerating by 22 percent in the period. The growth forecasts in the latest set of market analyst reports that indicate widespread adoption of biometrics technology: 22 percent for mobile biometrics, 22 percent for 3D sensors, and 19 percent for healthcare biometrics.
- OpenText – 2020 predictions from Anthony Di Bello, Vice President, Strategic Development, OpenText –
- Information Security Buzz - 2020 Cybersecurity Predictions by 50+ IndustryLeaders
“In light of the ever growing cybersecurity skills gap, and an exploding attack surface, infosec leaders will shift their focus from increasing headcount to increasing efficiency. By prioritizing tasks based on risk, solving the most impactful issues first, CISOs can ensure that even a small team can have maximum possible impact.”
- Information Age – The online magazine offers these Predictions for cyber security in 2020
Although cyber security teams may well have familiar viruses scouted, it’s important to remember that these kinds of attacks, much like their biological namesakes, can mutate.
“Cybercriminals are constantly redesigning Remote Access Trojans, or RATs, so they get better at bypassing security protections,” said Rowley.
- CSO Magazine - 2020 cybersecurity trends: 9 threats to watch - Here's how your biggest threats of 2019 will likely trend for 2020 and how you might change your defensive strategy for them.
- Crowdstrike & Auto Club Group CISO – While not an actual 2020 prediction report this Crowdstrike video and explanation blog does an excellent job showing how the “Speed of Onset” or “Breakout Time” is becoming a key factor in 'Cyber Risk Calculations' in addition to breach impact and likelihood. Gopal Padinjaruveetil, CISO at Auto Club Group, believes tracking this speed will become a major trend in 2020 – as expressed in the Information Security Community posting (of this piece) on LinkedIn.
- IBM – IBM X-Force Security Predictions for 2020 were a late arrival at their Security Intelligence portal. These predictions are always well done.
“Taking advantage of new privacy regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), motivated activists and attackers will flood companies with individual rights requests either as punishment for controversial views or as a distraction as a prelude to an attack. These rights, built into the regulations to allow you to request all the information a company has related to you, are a potential unintended attack vector that will be difficult to manage without proper processes in place to handle such requests at scale.” — Cindy Compert, IBM Security
- Digital Shadows - Another good list from Digital Shadows on 2020 Cybersecurity Forecasts: 5 trends and predictions for the new year
Mobile devices have taken center stage in the lives of just about everyone. We use them for shopping, banking, communication, and everything in between. This ever-increasing adoption of mobile devices has provided attackers with a large attack surface, something that could only be dreamed about ten years ago. The threat of mobile device targeting is only going to increase in 2020 and beyond as handheld devices continue to be prominent in our lives. Organizations should also be wary of the risk from Shadow IT, particularly as bring-your-own-device policies are becoming increasingly popular. Having comprehensive insight into devices connected to your corporate network can make all the difference in preventing inadvertent backdoors and data exposures. From cybercrime to nation-state cyber espionage, the threat of mobile device targeting is something that can affect anyone, from individual consumers up to Fortune 500 companies.
- Tech Republic – Here are Jack Wallen’s Cybersecurity in 2020: Eight frightening predictions
I believe there will be a data breach to end all data breaches, and it will happen in the cloud and affect billions of users. Chances are it will happen to a hybrid cloud that will lead the hackers down a rabbit hole that will gain them access to multiple cloud entities. This breach will cause a fundamental shift in how cloud providers handle security; look for serious changes to the authentication process of cloud providers by the end of the year.
- Arkose Labs - Arkose Labs Cyber Fraud Predictions for 2020
Excerpt: Rise of Mid-tier MSSPs:
In 2020, we will see a rise of the mid-tier MSSPs, as they are more focused on identifying the best tools to address specific cybersecurity challenges. The big channel partners on the other hand, are too focused on chasing money associated the sale of large, legacy providers that claim to “do it all.” Enterprises are increasingly frustrated with this approach and prefer partners with expertise on the latest, most effective security practices and solutions.
- AlienVault – AlievVault is actually now ATT&T Cybersecurity, but that doesn’t stop Javvad Malik from offering his 7 Real Security Predictions from AlienVault in InformationSecurityBuzz.com. When you read these seven, you can be forgiven if you think there is something a bit different about list. As he says at the end, “That’s because all of these predictions are not from today, in fact they were made 10 years ago in a blog post at Symantec.” A good reminder about learning from history, which is how we started this annual report.
In 2020, expect to see the propagators of rogue security software scams take their efforts to the next level, even by hijacking users’ computers, rendering them useless and holding them for ransom. A less drastic next step, however, would be software that is not explicitly malicious, but dubious at best. In these cases, users are technically getting the software that they pay for, but the reality is that this same software can actually be downloaded for free elsewhere.
- CRN – CRN.com offered these 5 Emerging Cybersecurity Trends To Watch In 2020. Good thoughts on potential security industry consolidation.
The endpoint security space has gotten a little less crowded over the past year as broad technology vendors pursue endpoint protection, detection and response capabilities. BlackBerry kicked the acquisition spree off in February by scooping up Cylance for $1.4 billion. Then in June, open-source search technology company Elastic announced plans to purchase Endgame for $234 million.
Two months later, Symantec announced plans to sell its struggling Enterprise Security division to semiconductor manufacturer Broadcom for $10.7 billion. And later in August, virtualization giant VMware announced plans to acquire Carbon Black in a transaction with an enterprise value of $2.1 billion.
Late-stage endpoint security startups like Tanium, Cybereason and SentinelOne will likely approach the point in 2020 where they’ll either need to conduct an initial public offering (IPO) or get acquired by an private equity firm or larger technology company. And as McAfee’s private equity owners look to exit their investment, media reports have indicated that the company could carry out an IPO.
- BAE Systems - Dr. Adrian Nish leads the Threat Intelligence team in BAE Systems cyber-defense division. His team tracks both criminal and national security threats to build a picture of the actors in terms of their motivation and capabilities. These insights feed the technical defensive systems deployed by customers as well as providing context for decision makers. Here are his 2020 Predictions from BAE Systems Applied Intelligence.
Human safety has become dependent on automated, connected, cyber-physical systems. Factory machinery, medical devices, autonomous vehicles or city energy distribution going down could be disastrous – impacting not just costs but human life. We have already seen cyber attacks disrupt access to basic resources with the BlackEnergy and Industroyer malware in 2015 and 2016 – it is only a matter of time until we see a cyber threat to human life.
If safety is compromised by an attributable state-sponsored cyber attack, this will draw the attention of governments and international law – the Secretary General of NATO Jens Stoltenberg has already made it clear that a cyber operation could trigger Article 5, and adversaries may choose 2020 to test that commitment. …
- nCipher - 2020 Predictions: What’s next for the cloud, connected cars and medicine, and cybersecurity
If you think vehicles that drive themselves sound like science fiction, you’re not alone. Many of us still think that autonomous cars sound pretty far out. And, in a sense, they are.
As we all know, autonomous vehicles exist in the real world today. However, that doesn’t mean we’ll see them out in force on Main Street any time soon. Instead, the majority of autonomous vehicles successfully coming to market will have a narrow scope and reach. ...
- Netskope - Jason Clark, the recognized industry expert and respected thought leader with Netskope, offers his Cybersecurity Predictions for 2020 in this blog.
Cloud Phishing Will Increase as a Primary Tactic for APTs.
Phishing attempts will primarily launch through cloud applications instead of emails. Users implicitly trust the many cloud applications used in the workplace, making them vulnerable to phishing tactics. Similarly, mobile devices are becoming the primary cloud access venue, which makes them attractive targets for phishing attacks that take advantage of the small screen form factor of mobile devices to lure users to open malicious content.
Accidental Exposure and Misconfiguration will Increase the Severity and Variety of Breaches
Cloud data breaches rooted in accidental exposure and misconfiguration of cloud applications will increase both in severity and in the number of different cloud apps that are affected. This aligns with Gartner’s prediction that by 2020, 95% of cloud security failures will be the customer’s fault. As cloud adoption continues to grow and more data is stored and shared in the cloud, exposure of that data is something that security teams will have to deal with.
2020 Security Prediction Awards
Top Security Industry Predictions Report - The New Norm: Trend Micro Security Predictions for 2020 - Trend Micro (for third year in a row.)
Individual Prediction that is Most Unique, Different and Insightful – “The unknown is the biggest cyber threat businesses will face.” Bugcrowd
Individual Prediction that is Most Creative — “Deepfakes-As-A-Service emerges.” ForcePoint
Individual Prediction that is Newest & Specific (2 Tie)— “False flag attacks reach a whole new level. Explanation: This will develop further, with threat actors seeking not only to avoid attribution but also to actively lay the blame on someone else. Commodity malware, scripts, publicly available security tools or administrator software, mixed with a couple of false flags, where security researchers are hungry for any small clue, might be enough to divert authorship to someone else.” Kaspersky
Also – “REAL ID will cause real chaos: As the October 2020 deadline looms, REAL ID will catch several states off guard.” Varonis
Individual Prediction that is Most Scary (yet practical) — “Hackers will find new low-hanging fruit in the cloud. The most advanced (and potentially devastating) cloud attacks will occur at machine speed in 2020.” Splunk
Individual Prediction that is Most Common and Likely — (3 Tie) – More Targeted Ransomware & Deepfakes cause (myriad) problems & various election hacks and misinformation campaigns will emerge (Numerous)
Topic of Most Disagreement Among Security Companies — Cloud –vs- mobile threats will take the lead – multiple companies on both sides. (Numerous – but more say cloud over mobile malware)
Best Overall Advice in Predictions Report — “We are all targets. If you work with a high value target, you are also a high-value target.” FireEye
Final Thoughts - What's Missing?
Just as I was preparing to release this report, Boris Johnson won a surprise landslide victory in the U.K. election – running on “Get Brexit Done.” (The polls predicted a small victory or hung Parliament.) This surprise result reminds us (again) that plenty of unknowns will emerge next year – making Bugcrowd’s quote about the unknown so relevant in cybersecurity.
Missing in the prediction lists again this year are specific predictions about hacks related to upcoming events (the U.S. election excluded from this comment which is covered by almost everyone.)
There is little about the 2020 Olympics or other major sporting events. Could Russia being banned from the Olympics and 2022 football World Cup lead to trouble? Or, could hacktivists disrupt world leaders meetings at the G8 or NATO or other various summits?
Finally, will cyber terrorism reemerge? Very few dire predictions (again) about Cyber 9/11s or Cyber Pearl Harbors or even people dying in hospitals from cyberattacks.
Could implanted chips become a big privacy debate and/or cause other security issues? I think so – but perhaps not in 2020. I do predict that this issue will be huge for the next decade and bring a new round of opposition from the privacy activists and others for religious and other reasons.
In closing, Boris Johnson pledged to unite the United Kingdom and heal its Brexit divisions in his speech after his victory.
2020, he said, would be 'a year of prosperity and growth and hope.'
That’s one prediction that I hope comes true for all of us around the globe, wherever you live, whether offline or online.