2019 was a bad year for data security. Based on reports and analyses, it was the worst ever. According to the Ponemon Institute and its report on data breaches, the average cost of data breaches reached $3.92 million, the highest amount ever recorded.

Simultaneously, the number of data breaches reached its highest recorded level and increased by 54% in the first half of 2019, with nearly 4,000 breaches publicly disclosed during this period. Overall, 2019 saw more than 4.1 billion records exposed on the worldwide web.
More and more often, consumers and regulators hold companies responsible for data breaches. A study from October 2019 concluded that 81% of consumers would stop dealing with a company or product after a data breach, which means that the defamation of a company and the damage to its reputation that accompanies a breach are likely to increase the cost of a data security incident.
Additionally, regulatory mandates like GDPR and CCPA are indicative of a trend that collectively increases the importance of data security in the coming year. For those charged with protecting a company’s data, today’s multi-threat landscape can feel chaotic, leading to increased levels of burnout.
However, not all threats are equally terrifying, as some are more likely and more malicious than others. Cybercriminals are evolving their tactics as the security industry deals with incidents in cyberspace and weighs the advantages of paying ransoms.
With malicious software bugs turning into new threats and regulators closely monitoring any mistakes, companies are relying on cybersecurity teams more than ever.
Here are 5 trends for cybersecurity:
- Security is integrated into data science
Data gives companies a competitive advantage. Data scientists leverage AI algorithms, which are available in open source, to modify and shape unified AI models. But AI models are based on quality data, scalable computing power, and reliable algorithms.
The cloud has lifted the constraints of IT and has allowed companies to modernize quickly, sometimes leaving ethical concerns behind. The application of AI exceeds the «clear and ethical consent», «threatening the already high rates of participation in users' private lives».
“Algorithms and the handling of personal data will become more accessible”, said Lenley Hensarling, head of strategy at Aerospike. “At the same time, data handling will become more careful.” Data processing is more dangerous for businesses than its collection, according to Gartner.
The de-anonymization, the increase of data sources and the various definitions of privacy contribute to a more complex landscape that requires protection. “Regulatory authorities, as well as a large part of the public, are becoming increasingly aware of the data they share, both personal and other, as well as their usage”, said Hensarling.
- Ransomware are increasing to a crisis level
The ransomware occurred last year in the industry, affecting entities such as government administrations, healthcare facilities and school sectors. The hackers behind GandCrab stopped the ransomware's operation last year, as the successor REvil made its debut. In 2019, McAfee stated that there will be “stronger malicious software”, as the hackers will collaborate to establish their dominance. The people behind GandCrab abandoned the ransomware to focus on its successor REvil.
Hackers who use ransomware have taken encryptions to an advanced level, threatening to disclose or sell stolen data to competitors.
- Companies are betting on machine learning
To combat human error in security, companies are upgrading their capabilities in machine learning (ML). “The security industry has a real opportunity in 2020 to solve certain problems that could not be solved”, said Larkins.
From the era of “static technology”, cybersecurity is becoming more agile. Cloud and data security represent a much smaller portion of security spending, costing 15 and 72 million dollars respectively, according to Gartner. However, they constitute the fastest-growing risk management sector.
“What we’re trying to do is not remove humans from these processes, but make it easier for them to process them,” said Matt Scholl, head of the computer security division at the National Institute of Standards and Technology (NIST). Machine learning has the potential to violate privacy. Companies that use it to conduct experiments and reach conclusions “through this kind of discovery process, using machine learning algorithms and large data sets, risk the possibility of privacy issues if they don’t properly lock down the algorithms and the data,” Scholl said.
Software vendors are likely to expand their offerings to more closely address management related to privacy. “Just like security, privacy concerns people, processes and technology,” said Scholl.

- Service provider companies are noticing the increasing attacks
The malicious actors moved past 2019 by sending ransomware to smaller entities, but they were also collateral victims. Service providers (MSPs) will continue to be in hackers' sights. Companies face challenges balancing validation and user experience. “Operational efficiency often creates problems until security standards are reduced.” As a result, service provider customers feel the impact of their cyber attacks.
The attacks on remote monitoring and management software used by providers and other remote access solutions “allow simultaneous attacks on multiple companies”, according to Callow. In one case, more than 400 customers were affected by an attack, according to Emsisoft. MSP CyrusOne was hit in December, affecting the availability of six of its customers.
At least 13 entities or service providers based in the cloud were affected by ransomware in 2019. The attacks on service providers were “entirely predictable and could have been avoided,” according to Emsisoft. With data theft as another threat, cyber attacks create “the possibility that the data of many organizations could be stolen with a single blow”.
Custom remote access solutions, protected with two-factor or multi-factor authentication or fully disabled, mitigate the risk. “Furthermore, they must ensure that their service providers follow best practices”, said Callow. Service providers, in response to the series of ransomware attacks, have implemented cyber solutions instead of the recommended preventive measures.
- Tools and security protocols as protection of privacy
There are no specific tools for protecting privacy, but there are mechanisms for protecting consumer data. Companies will continue to rely on existing security tools to prevent incidents that put consumer data at risk. Data breaches jointly link the consequences of security and privacy.
This year, privacy regulatory authorities fined Marriott International and British Airways for failing to securely protect their customers' data. Capital One suffered a data breach after exploiting a flaw in the web application firewall (WAF). WAFs contribute to cybersecurity strategies that focus on protecting the perimeter rather than the data.
Privacy is a byproduct of security protocols in cyberspace. Organizations state that IT security teams are responsible for protecting privacy.
“Security teams provide the tools for safe and careful handling of personal information”, said Hensarling. However, 95% of C-suite executives have 20% or less security capital in cyberspace for identifying solutions.
Legacy systems complicate the development of identity solutions and companies have not managed to develop systems based on APIs compatible with application integration.
