Eight Ways Cyber Threats & Business Security Will Change in 2018

As cyber-attacks increasingly threaten business and grow in volume and scale, companies will be forced to take new measures to address cybersecurity risk holistically, integrating it more aggressively into their enterprise risk management, according to insurance broker Aon’s cyber specialists in the firm’s 2018 Cybersecurity Predictions report.
 
The report outlines specific actions that Aon believes companies will take in 2018 to address cyber threats, as well as other cyber trends that it anticipates in the new year.
 
“In 2017, cyber attackers created havoc through a range of levers, from phishing attacks that influenced political campaigns to ransomware crypto-worms that infiltrated operating systems on a global scale. 
 
“With the growth of the Internet of Things (IoT), we have also witnessed a proliferation of distributed denial-of-service (DDoS) attacks on IoT devices, crippling the device’s functionality,” said Jason J. Hogg, CEO, Aon Cyber Solutions. Hogg said Aon’s specialists expect heightened cyber exposure due to a convergence of three trends: companies’ increasing reliance on technology; regulators’ intensified focus on protecting consumer data; and the rising value of non-physical assets.
“Heightened exposure will require an integrated cybersecurity approach to both business culture and risk management frameworks,” he said. “Leaders must adopt a coordinated, C-suite driven approach to cyber risk management, enabling them to better assess and mitigate risk across all enterprise functions.”
 
Aon’s 2018 Cybersecurity Predictions report look at the ways in which the increasing scale and impact of cyber-attacks, coupled with companies having to accept more liability and accountability over cyber-attacks, will lead to significant changes in the corporate landscape. 
 
The report predicts an expanding role for the chief risk officer (CRO), the importance of implementing multi-factor authentication, the increased threats from insiders, and an expansion of bug bounty programs in new sectors.
Here are eight ways Aon’s specialists see cyber risks and cybersecurity playing out during this year:
 
1. Businesses adopt standalone cyber insurance policies as boards and executives wake up to cyber liability. 
As boards and executives experience and witness the impact of cyber-attacks, including reduced earnings, operational disruption, and claims brought against directors and officers, businesses will turn to tailored enterprise cyber insurance policies, rather than relying on “silent” components in other policies. 
 
Adoption will spread beyond traditional buyers of cyber insurance, such as retail, financial, and healthcare sectors, to others vulnerable to cyber-related business disruption, including manufacturing, transportation, utility, and oil and gas.
 
2. As the physical and cyber worlds collide, chief risk officers take center stage to manage cyber as an enterprise risk. 
As sophisticated cyber-attacks generate real-world consequences that impact business operations at increasing scale, C-suites will wake up to the enterprise nature of cyber risk. In 2018, expect CROs to have a seat at the cyber table, working closely with chief information security officers (CISOs) to help organisations understand the holistic impact of cyber risk on the business.
 
3. Regulatory spotlight widens and becomes more complex, provoking calls for harmonisation. 
EU holds global companies to account over General Data Protection Regulation (GDPR) violation; big data aggregators come under scrutiny in the US. 
 
In 2018, regulators at the international, national and local levels will more strictly enforce existing cybersecurity regulations and introduce new regulations. Expect to see EU regulators holding major US and global companies to account for GDPR violations. 
 
Across the Atlantic, big data organisations (aggregators and resellers) will come under scrutiny on how they are collecting, using, and securing data. Industry organisations will push back on regulators, calling for alignment of cyber regulations.
 
4. Criminals look to attack businesses embracing the Internet of Things, in particular targeting small to mid-sized businesses providing services to, global organisations. 
 
In 2018, global organisations will need to consider the increased complexities when it comes to how businesses are using the IoT in relation to third-party risk management. The report predicts large companies will be brought down by an attack on a small vendor or contractor that targets the IoT, using it as a way into their network. 
 
This will serve as a wake-up call for large organisations to update their third-party risk management, and for small and mid-sized businesses to implement better security measures or risk losing business.
 
5. As passwords continue to be hacked, and attackers circumvent physical biometrics, multi-factor authentication becomes more important than ever before. 
 
Beyond passwords, companies are implementing new methods of authentication – from facial recognition to fingerprints. 
However, these technologies are still vulnerable and as such, the report anticipates that a new wave of companies will embrace multi-factor authentication to combat the assault on passwords and attacks targeting biometrics. 
 
This will require individuals to present several pieces of evidence to an authentication instrument. With the new need for multi-factor authentication, and consumer demand for unobtrusive layers of security, expect to see the implementation of behavioral biometrics.
 
6. Criminals will target transactions that use reward points as currency, spurring mainstream adoption of bug bounty programs: Companies beyond the technology, government, automotive and financial services sectors will introduce bug bounty platforms into their security programs. 
 
As criminals target transactions that use points as currency, businesses with loyalty, gift and rewards programs, such as airlines, retailers, and hospitality providers, will be the next wave of companies implementing bug bounty programs. 
As more organisations adopt the programs, they will require support from external experts to avoid introducing new risks with improperly configured programs.
 
7. Ransomware attackers get targeted; cryptocurrencies help ransomware industry flourish. In 2018, ransomware criminals will evolve their tactics. 
 
The report predicts that attackers utilising forms of benign malware, such as software designed to cause DDoS attacks or launch display ads on thousands of systems, will launch huge outbreaks of ransomware. 
 
While attackers will continue to launch scatter-gun-style attacks to disrupt as many systems as possible, the report predicts an increase in instances of attacks targeting specific companies and demanding ransomware payments proportional to the value of the encrypted assets. 
 
Cryptocurrencies will continue to support the flourishing ransomware industry overall, despite law enforcement becoming more advanced in their ability to trace attacks, for example through bitcoin wallets.
 
8. Insider risks plague organisations as they underestimate their severe vulnerability and liability while major attacks fly under the radar.  In 2017, businesses underinvested in proactive insider risk mitigation strategies, and 2018 will be no different. 
According to the report, a continued lack of security training and technical controls, coupled with the changing dynamics of the modern workforce, the full extent of cyber-attacks and incidents caused by insiders will not become fully public. 
 
Many companies will continue to reactively respond to incidents behind closed doors and remain unaware of the true cost and impact of insider risk on the organisation.
 
Insurance Journal:             Strozifriedberg.com / Aon:
 
You Might Also Read: 
 
Leaving Hacks Behind - Cybersecurity Predictions for 2018:
 
Cyber Insurance Report 2017 - 2018 (£):
 
Offensive Security, Cyber Insurance & Cryptocurrencies: 2018 Predictions?:
 
 
« GDPR For Dummies
The AI Lock In Loop »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

8MAN

8MAN

8MAN is a leading Access Rights Management (ARM) solution in Microsoft and virtual server environments.

Centre for Development of Advanced Computing (C-DAC)

Centre for Development of Advanced Computing (C-DAC)

C-DAC is the premier R&D organization of the indian Ministry of Electronics & Information Technology. Areas of research include cyber security.

Exprivia

Exprivia

Exprivia is active in the design, development and integration of IT systems including cyber security.

Securepoint

Securepoint

Securepoint is the market leader in the development of professional “Unified Threat Management” solutions in Germany.

Haechi Audit

Haechi Audit

Haechi Audit is a leading smart contract security audit firm. We provide the most secure smart contract security audit and smart contract development services to our global clients.

Swarmnetics

Swarmnetics

Swarmnetics helps customers discover hard-to-find software vulnerabilities by hacking your system before the bad guys do.

Sevatec

Sevatec

Sevatec’s Active Cyber Defense (ACD) methodology proactively defends against adversarial kills chain, addressing active and emerging threats while reducing program vulnerabilities and risks.

SEIRIM

SEIRIM

SEIRIM delivers cybersecurity solutions in Shanghai China specializing in Web Application Security, Network Security for SME's, Vulnerability Management, and serving as Managed Security as a Service.

Mailinblack

Mailinblack

Mailinblack protects your organisation against email threats with an innovative solution that meets your security requirements.

Josef Ressel Centre for Intelligent & Secure Industrial Automation

Josef Ressel Centre for Intelligent & Secure Industrial Automation

The Josef Ressel Centre for Intelligent and Secure Industrial Automation investigates the fundamentals of digital assistants for industrial machines that enable intelligent and secure operation.

CyberSecAsia

CyberSecAsia

CyberSecAsia series conference is the one and only decision-makers gathering for CISO and info security experts in Asia.

Enterprise Strategy Group

Enterprise Strategy Group

Enterprise Strategy Group, a division of TechTarget, is an IT analyst, research, validation, and strategy firm that provides market intelligence and actionable insight to the global IT community.

M6iT Consulting

M6iT Consulting

M6iT Consulting is an industry-leading solution partner managing the IT requirements for a full range of companies.

Valmet

Valmet

Valmet is a leading global developer and supplier of process technologies, automation and services for the pulp, paper and energy industries.

Scytale

Scytale

Scytale is the global leader in security compliance automation, helping companies get compliant and stay compliant.

iOT365

iOT365

iOT365 is the first-of-its-kind SAAS platform dedicated exclusively to Operational Technology (OT) security.