ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Evolutions in cyber security: predictions for 2022

2022 predictions large.jpg
2022 predictions large.jpg

Reflecting on the past year, 2021 has been turbulent for the cyber-security industry and we can expect this to be the case in 2022. Cyber-crime and cyber-attacks are at unprecedented numbers and the increased cyber risks will continue into the new year.

 

To understand what we can anticipate in 2022, teiss spoke to five cyber-security professionals to get some insight into their top concerns and predictions going forward.

 

Weaponizing key vulnerabilities

Callum Roxan at F-Secure: The exploitation of high-profile vulnerabilities will continue to dominate news cycles in 2022. We are seeing a widening group of threat actors investing in the discovery and weaponization of vulnerabilities in key technologies (VPNs, firewalls, IT management, and other externally facing popular infrastructure).

 

We can expect to see a growth in the exploitation of cloud management planes and the technologies used to authenticate and manage SaaS solutions by enterprises. An interesting point to note is that there will be an increase in the growth in cyber security maturity assessment-related services, which will be fuelled by more stringent risk management from insurers and incident response readiness services.

 

There will be an industry switch in focus from adding additional products and services to a stack, to consolidating these into a single solution. There will be an overarching trend of attempting to reduce complexity and simplify security, helping to define a new industry standard.

 

Growth in cyber security skills and competency training services is something we will see as organisations look to invest in people for greater returns, training and developing their skills. This comes due to the increased demands in the industry and because there is not enough skilled labour to meet those demands.

 

Phishers up their game

Peter Stelzhammer at AV-Comparatives: Cyber-criminals are getting better and better at producing highly convincing spear phishing emails. We expect to see phishing continue to be one of the primary attack methods targeting organisations in 2022. 

 

Spoofing is a criminal art that is becoming increasingly refined. However, there are relatively simple tactics emerging which will pose a threat over the coming years. Can you see the difference between the words “Paypal” and “PayPal”? Probably not. The last letter in the second word is a capital “i”. If you received an email from a @paypaI.com address using this simple trick, you might easily think it was genuine. Yet it would be from a false malicious domain, meaning that it is likely to be a phishing email designed to steal credentials. 

 

The sophistication of spoofing will grow in the coming year – but rudimentary techniques will also continue to cause problems. Businesses and individuals need to be on high alert and query every email, no matter if it looks genuine or not. CEO fraud is an example of a threat that isn’t going to go away. It illustrates a simple point. If you get an email asking you to transfer money, just call the person the message appears to come from. This will take you one minute and could save a lot of money. Small steps can have a big effect on security.

 

Cyber threat visibility and detection increase in importance

Todd Carroll at CybelAngel: In 2022, we will see a pivot from thought leaders in the industry to include a new understanding and better calculation of risk in the digital world. 2021 showed us many changes from replacing traditions in the workforce, to adaptations in cloud implementation. As well, we saw multiple, successful supply chain attacks - and what is clear is that all these factors are viable and here to stay.

 

The cyber risk now needs to be assessed at greater speed and the protection of IP and data within the whole IT ecosystem, including third parties and business relationships, should be considered. As a result, traditional cyber-CISO Role will broaden their approach to early detection, awareness and visibility of critical data and not only just responding to an attack. 

 

Misdirection and concealment rise to the forefront of cyber defence

Carolyn Crandall at Attivo Networks: With the assumption that attackers can and will get inside networks, companies will see a greater need for in-network lateral movement prevention and privilege escalation defence measures. Uncovering and derailing attacks in real-time requires proactive concealment to hide and deny access to assets (credentials, Active Directory objects, and data) and decoys to misdirect attackers away from their targets.

 

With the speed of attacks today, businesses need proactive visibility and measures that detect attacker lateral movement. The focus centres on preventing the attacker from breaking out from its initial infected system regardless of whether it is a managed or unmanaged device.

 

Cryptocurrencies are here to stay

Joseph Carson at ThycoticCentrify: Cryptocurrencies are surely here to stay and will continue to disrupt the financial industry, but they must evolve to become a stable method for transactions and accelerate adoption. Some countries have taken a stance that energy consumption is creating a negative impact, and therefore facing decisions to either ban or regulate cryptocurrency mining. 

 

Meanwhile, several countries have seen cryptocurrencies as a way to differentiate their economies so they can become more competitive in the tech industry and persuade investment. In 2022, more countries will look at how they can embrace cryptocurrencies while also creating more stabilisation, and increased regulation is only a matter of time. Stabilisation will accelerate adoption, but how the value of cryptocurrencies will be measured is the big question. How many decimals will be the limit?


Callum Roxan is Head of Threat Intelligence at F-Secure; Peter Stelzhammer is Co-Founder of AV-Comparatives; Todd Carroll is CISO at CybelAngel; Carolyn Crandall is Chief Security Advocate at Attivo Networks; and Joseph Carson, Chief Security Scientist at ThycoticCentrify

 

Main image courtesy of iStockPhoto.com

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543