Security Trends For 2022 - The Need For Talent & Cloud Migration

It’s been another challenging 12 months in cyber security with several major breaches during an already turbulent year. 
 
We saw the damaging ransomware attack on Colonial Pipeline, one of most high profile security stories of the year. The attack shut down a 5,500-mile-long pipeline on the east coast of the US, fueling fears over risks to critical infrastructure and global supply chains. 

 
In May, we saw President Biden sign an executive order designed to tackle the nation’s cybersecurity issues head-on, including supply chain security, and, perhaps the most important order of business, a call for government agencies to adopt a zero trust approach.
 
It’s also been the year of crypto currencies, deepfake technology and growth in fraud and scams associated with the pandemic.
 
As we look ahead to another 12 months in the industry, we focus on two trends for 2022.

1. Impact Of The Talent Shortage 

Microsoft  announced a partnership recently with community colleges around the US to provide free resources in an attempt to help end the shortage in cybersecurity professionals by 2025. The question is whether this shortage of readily available talent will impact the security industry over the next year or so and how technology can help to mitigate this. 
 
In the immediate future, the talent shortage will remain a problem. We have found this ourselves. It is getting better, but more investment is needed. People are recognising that security is an interesting and lucrative career, but there aren’t enough people and I think there will always be a struggle to keep up with growing demand. 
 
Look at it from a technology perspective, and it stands to reason that if there are less security incidents to manage, there is less need to recruit new talent into the industry and the impact of the talent shortage will be greatly reduced. 
 
We need to give them the tools that they were hiring services to do in the first place. The shortage is not going away any time soon so solutions need to be built around it. Better solutions will mean fewer incidents.
 
We need automation of solutions and automatic remediation. These tools will need to adapt to changing environments and to be built with a more holistic approach in mind, off-premises, on-premises, in the cloud and in a hybrid environment as work models evolve. 
 
All of this falls under the umbrella of zero trust, and this is the blueprint that businesses should be using as the building blocks to robust security. 
 
2. A Move To The Cloud Will Finally Happen 

While other industries moved operations to the cloud some time ago, there has been some hesitation to shift away from on-premises operations for security leaders. 
 
With the increase in sophisticated threats coming through as many employees work remotely, security leaders can no longer depend on legacy systems for protection, but instead need to shift to cloud native solutions. Factors, such as the increase in ransomware attacks, may influence more security leaders to finally move to cloud based solutions. 
 
But what will drive people and businesses to move to the cloud is the need to do security better. It stands to reason that if they need to improve their approach with security then the cloud is almost certainly going to be the way to go.
 
We are also seeing the pendulum beginning to swing in the favour of the user experience. The emphasis is on how you can carry out your job without negatively impacting the workflow processes and the device choice for the end user. Users must be able to work as and when they expect to and as fast as usual, but security is still implemented. 
 
This points all to the cloud because you need that scalability, you need that global view, device coverage, and you need to be in between the end user and the cloud services that they are accessing. 

Mark Guntrip is Senior Director, Cybersecurity Strategy at Menlo Security

You Might Also Read:

Cyber Security In 2022:

 

« Are Remote Contractors A Cyber Security Risk?
Education Should Focus On Cyber Security »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ON-DEMAND WEBINAR: Gen AI for Security: Adoption strategies with Amazon Bedrock

ON-DEMAND WEBINAR: Gen AI for Security: Adoption strategies with Amazon Bedrock

Watch this webinar and get a comprehensive roadmap for securely adopting generative AI using Amazon Bedrock, a fully managed service that offers a choice of high-performing foundation models (FMs).

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

UCD Centre for Cybersecurity and Cybercrime Investigation

UCD Centre for Cybersecurity and Cybercrime Investigation

UCD Centre for Cybersecurity and Cybercrime Investigation is Europe's leading centre for research & education in cybersecurity, cybercrime and digital forensics.

a1qa

a1qa

a1qa specializes in the delivery of full-cycle software QA and application testing services.

High Sec Labs (HSL)

High Sec Labs (HSL)

High Sec Labs develops high-quality, cyber-defense solutions in the field of network and peripheral isolation.

London Office for Rapid Cybersecurity Advancement (LORCA)

London Office for Rapid Cybersecurity Advancement (LORCA)

LORCA's mission is to support the most promising cyber security innovators in growing solutions to meet the most pressing industry challenges and build the UK’s international cyber security profile.

CryptoCurrency Certification Consortium (C4)

CryptoCurrency Certification Consortium (C4)

The CryptoCurrency Certification Consortium is a non-profit organization that provides certifications to professionals who perform cryptocurrency-related services.

Cyber Security Africa

Cyber Security Africa

Cyber Security Africa is a full-service Information Security Consulting firm offering a comprehensive range of Services and Products to help organizations protect their valuable assets.

Penten

Penten

Penten is an Australian-based cyber security company focused on innovation in secure mobility and applied AI (artificial intelligence).

Seknox

Seknox

Seknox TRASA™ protects your business from insider threats.

DeepSeas

DeepSeas

DeepSeas is the result of a merger between Security On-Demand (SOD) and the commercial Managed Threat Services (MTS) business of Booz Allen Hamilton.

CyberHunter Solutions

CyberHunter Solutions

CyberHunter is a leading website security company that provides penetration testing, Network Vulnerability Assessments, cyber security consulting services to prevent cyber attacks.

PSafe

PSafe

PSafe is a leading provider of mobile privacy, security, and performance apps. We deliver innovative products that protect your freedom to safely connect, share, play, express and explore online.

SecurelyShare Software

SecurelyShare Software

SecurelyShare Software is a security software company, specializing in data security, data privacy and data governance.

Support Link Technologies (SLT)

Support Link Technologies (SLT)

Support Link Technologies are an IT Solutions Company committed to achieving customer satisfaction through excellent customer service.

Lavabit

Lavabit

Lavabit's Dark Internet Mail Environment is a secure, open-source, secure end-to-end communications platform for asynchronous messaging across the internet.

Avocado Consulting

Avocado Consulting

Avocado helps clients deliver with certainty on their complex IT change, with technology services that automate, monitor and optimise.

Revytech

Revytech

Revytech is a tech company providing services in a broad range of areas including IT operations, cyber security and network engineering.