As the year draws to a close and we look ahead to 2016, Symantec Corp. experts are providing their own predictions on the threats expected to threaten cybersecurity.
Safety by design
The IoT (Internet of Things), without built-in security, will continue to be vulnerable, thus making it an IoV (Internet of Vulnerabilities).
Consumers
Malicious attackers are seizing the opportunities that arise for attacks against IoT devices as the number of connected and networked devices continues to grow. Of course, the number of applications is still relatively small, so large-scale attacks on consumers in this area are not expected. However, there will be occasional smaller outbreaks and early adopters should be cautious. We expect ad-clicking and ransomware attacks to be among the first types of attacks to truly impact cybercrime on IoT devices.
Attacks on connected medical devices or cars pose a real security threat and this may mean that regulations and terms will need to be set. Certificates and code signing will play a very important role in securing IoT devices but as we move forward, security will need to be built into IoT devices from the design stage.
Industry
In the interconnected industry, huge productivity increases are expected, but also a large volume of attacks, which means that many companies will need to be properly shielded. The interruption of the production process due to external attacks or failures will certainly be a challenge for companies to adopt and develop Industry 4.0, but there will be a rather difficult path towards connectivity. Data protection strategies and telemetry threats will have to evolve. We believe that CISOs, based on each company, will take a comprehensive approach to the security of their IT infrastructure by establishing specific levels of protection. Integrating the principle of security from the design of even devices to how they will produce new technologies will be crucial for the coming years. Whether we are referring to the design of smart cities, infrastructure or the various robots that will take on an increasingly larger role in everyday life, they must be secured in their programming, upgrading and identification. The environment in which these new technologies evolve must have these principles at its core to be sure of security and the avoidance of threats at later stages.
Privacy and data protection
“Is it safe?”: Consumers’ Doubt About Data on Wearables
The battle over privacy has been dominated by the apathy and convenience of recent years, and the security industry is often asked: How much security are we willing to give up for an easy life? As wearables become more widely adopted by the general public, more and more data is being collected and there is increasing competition for systems and devices. Customers, businesses and governments will start to ask reasonable questions such as: Where exactly is my data going? What is it used for? Is it safe?
Symantec Covering our backs: insurance, liability and terms
Cybersecurity: Ensuring good behavior
With the high volume of breaches that occurred in 2015, cyber insurance seems to be an inevitable solution for both businesses and individuals. The prefix “cyber” and “cyberspace” clauses will become commonplace for all of us, and it is likely that greater responsibility will have to be placed on consumers and businesses to adopt safe practices or risk exposure from insurers. For businesses, this means procedures, training and education of staff. For consumers, it means greater control over the data they share.
Privacy legislation will go a step further
The upcoming European Data Protection Directive will clarify the landscape when it comes to data governance in the European Union. Organizations must comply with new requirements around the processing of personal data and introduce stricter compliance rules. This is a challenge even for the most informed and has raised concerns about the complexity of new information management processes and increasing costs. However, all this is necessary for people to realize the true potential of the internet and new technologies. This will put priorities and appropriate safeguards in place to ensure the protection of personal data.
Symantec The evolution of the threat landscape
Blurred lines between nationstate and lonewolf attacks
The level of sophistication previously associated with state-sponsored attacks will be strongly seen in lonewolf attacks. The number of hacking groups conducting sophisticated targeted attacks will blur the line between common cybercrime and targeted attacks. We will see more and more “real world” conflicts playing the role of cybercrime, with new, political motives and new emerging players.
Attacks on demand
Targeted attacks on governments and businesses will become even more targeted, due to the increasing professionalism of hacking groups. To avoid detection and maintain control over security, attacks will now be designed according to the purpose they want to accomplish. Each victim will have a unique C&C server, newly created malware and various attack vectors. This will make it even more difficult to detect attacks with simple IoC indicators – Indicators of Compromise, as advanced methods of correlation between industries and countries will be required.
“Hacking groups will continuously improve by covering their tracks and distracting attention away from their targets. They will better implement operational security in backend infrastructures, making takedowns and identifying stolen data and their performance even more difficult. To avoid early detection, encrypted communications using SSL will be used, and common cybercriminal Trojans will be developed to align with massive traditional cyberattacks.” (Candid Wueest, Threat Researcher at Symantec)
“This development will trigger increased transparency and collaboration in the SecurityAnalytics space. It will certainly take some time for all of this to happen, but in 2016 we expect to see an increase in the distribution of anonymous security telemetry. As a result, it is likely that some interesting new partnerships will emerge during this period.”
(Darren Thomson, CTO and VP of Technology, EMEA)
Rise of digital ransom
“Extortion scams will continue to grow in popularity, as they are profitable, relatively simple, and offer vengeful entertainment for those who seek attacks for fun rather than financial gain. Crypto ransomware will increase, holding data as ransom in return. However, we will also see growth in cases where an attacker threatens public disclosure. These cases will be similar to the newer strains of Chimera ransomware or the cases after the Ashley Madison breach. For enterprises, we expect blackmail to play a larger role in breaches.” (Candid Wueest, Threat Researcher)
Mobile security breach
The number of new Android malware types is likely to remain high or even increase further. With more and more features such as authentication tokens, enterprise applications, payments and other functions, it seems that smartphones and mobile devices in general will be one of the primary targets for attackers. We are likely to see stricter controls on the application market, while many companies will focus on making it harder to compromise the system's functions.
Breaches break identities
Due to the sheer volume of breaches in 2015, organizations may see the login/password system as broken and will want to change that system. Two-factor authentication (2FA), especially one that requires not only something the real owner knows, e.g., a password, but also something only they have, for example, their mobile phone, will now become commonplace. Biometric systems will also start to evolve into more comprehensive and mature solutions. We will also start to hear about “ECG-based identification” and “vein matching” as we realize that fingerprints are quite easy to copy.
Looking towards security in 2016 and beyond
- Safety by design for robotics
Robots will take over many everyday tasks and tasks over the next 10 years. This should include safeguarding from the design stage, to ensure that they are programmed, upgraded and identified, so that the environment in which they will be produced is as safe as possible and to avoid potential threats at a later stage.
- 3D City Modeling
True, “smart” cities are still a long way off, but the design and planning of these future spaces will be well advanced in 2016. The first applications of technology in this area will be immersive and customizable 3D models of future cities that will allow designers and other stakeholders to experience future designs through virtual reality. This also requires a guarantee from a design approach.
