{"id":532,"date":"2015-01-16T01:12:37","date_gmt":"2015-01-16T01:12:37","guid":{"rendered":"http:\/\/techbeatph.com\/wproot\/?p=532"},"modified":"2016-12-13T03:51:08","modified_gmt":"2016-12-13T03:51:08","slug":"sophos-releases-2015-cybersecurity-predictions-report","status":"publish","type":"post","link":"https:\/\/www.techbeatph.com\/wproot\/sophos-releases-2015-cybersecurity-predictions-report\/","title":{"rendered":"Sophos Releases 2015 Cybersecurity Predictions Report"},"content":{"rendered":"<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_20747\" align=\"center\"><\/div>\n<div><img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-533 aligncenter\" src=\"http:\/\/techbeatph.com\/wproot\/wp-content\/uploads\/2015\/01\/images-12.jpg\" alt=\"images (1)\" width=\"373\" height=\"135\" \/><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12902\">MANILA, Philippines \u2013 December 17, 2014 \u2013Sophos today released the <a id=\"yui_3_16_0_1_1421281345919_28495\" href=\"https:\/\/www.sophos.com\/en-us\/threat-center\/medialibrary\/PDFs\/other\/sophos-trends-and-predictions-2015.pdf\" target=\"_blank\" rel=\"nofollow\"><span id=\"yui_3_16_0_1_1421281345919_28494\" style=\"color: #196ad4;\">Security Threat Trends 2015<\/span><\/a> report that exposes the biggest security risks on the horizon and explains the real-world impact of evolving cyber threats on businesses and consumers in the New Year. After a year of big data breaches like Home Depot and Sony, it\u2019s easy to predict that cyber security will be a hot topic in 2015.<\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12915\"><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12917\">The <a href=\"https:\/\/www.sophos.com\/en-us\/threat-center\/medialibrary\/PDFs\/other\/sophos-trends-and-predictions-2015.pdf\" target=\"_blank\" rel=\"nofollow\"><span style=\"color: #196ad4;\">full report<\/span><\/a><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_12916\"> highlights the following 10 areas Sophos experts believe will have the biggest\u00a0impact on security in 2015 and beyond:<\/span><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12918\"><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12921\"><strong id=\"yiv1194643178yui_3_16_0_1_1421361866845_12920\"><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_12919\">1. Exploit mitigations reduce the number of useful vulnerabilities.<\/span><\/strong><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12923\"><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_12922\">Cybercriminals have for years feasted on Microsoft Windows. Fortunately, Microsoft has invested in exploit mitigations, which makes writing attack code more difficult. As the difficulty of exploitation increases, some attackers are moving back to social engineering, and we also see attackers focusing on non-Microsoft platforms.<\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28501\"><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12926\"><strong id=\"yiv1194643178yui_3_16_0_1_1421361866845_12925\"><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_12924\">2. Internet of Things attacks move from proof-of-concept to mainstream risks.<\/span><\/strong><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12928\"><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_12927\">In 2014 we\u2019ve seen more evidence that manufacturers of Internet of Things (IoT) devices have failed to implement basic security standards, so attacks on these devices are likely to have nasty real world impact. The security industry needs to evolve to deal with these devices.<\/span><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12929\"><strong>\u00a0<\/strong><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12930\"><strong>3. Encryption becomes standard, but not everyone is happy about it.<\/strong><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_12932\"><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_12931\">With growing awareness of security and privacy concerns due to revelations of intelligence agency spying and newsworthy data breaches, encryption is becoming more important than ever, though not without controversy. Certain organizations like law enforcement and intelligence agencies are unhappy about the prospect of pervasive encryption under the belief that it may adversely impact safety.<\/span><\/div>\n<div><strong>\u00a0<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28525\"><strong id=\"yui_3_16_0_1_1421281345919_28524\"><span id=\"yui_3_16_0_1_1421281345919_28523\">4. More major flaws in widely-used software that had escaped notice by the security industry over the past 15 years.<\/span><\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28503\"><span id=\"yui_3_16_0_1_1421281345919_28502\">From Heartbleed to Shellshock, it became evident that there are significant pieces of insecure code used in a large number of our computer systems today. The events of 2014 have boosted the cybercriminals\u2019 interest in typically less-considered software and systems \u2013 so businesses should be preparing a response strategy.<\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28526\"><strong>\u00a0<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28504\"><strong>5. Regulatory landscape forces greater disclosure and liability, particularly in Europe.<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28505\"><span id=\"yui_3_16_0_1_1421281345919_28527\">The law moves slowly compared to the technology and security fields, but massive regulatory changes that have been a long time coming are nearly here. It is likely these changes will trigger consideration of more progressive data protection regulation in other jurisdictions.<\/span><\/div>\n<div><strong>\u00a0<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28508\"><strong id=\"yui_3_16_0_1_1421281345919_28507\"><span id=\"yui_3_16_0_1_1421281345919_28506\">6. Attackers increase focus on mobile payment systems, but stick more to traditional payment fraud for a while.<\/span><\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28529\"><span id=\"yui_3_16_0_1_1421281345919_28528\">Mobile payment systems were the talk of 2014 after Apple stormed ahead with Apple Pay. Cybercriminals will be looking for flaws in these systems, but the present designs have several positive security features. Expect cybercriminals to continue abusing traditional credit and debit cards for a significant period of time as they are the easier target for now.<\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28509\"><strong>\u00a0<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28530\"><strong>7. Global skills gap continues to increase, with incident response and education a key focus.<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28532\"><span id=\"yui_3_16_0_1_1421281345919_28531\">As technology becomes more integrated in our daily lives and a supporting pillar of the global economy, the cybersecurity skills shortage is becoming more critical and broadly recognized by governments and industry. This gap is growing larger with some governments forecasting a widening gap through the year 2030 given the present scarcity of qualified IT security professionals.<\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28533\"><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28534\"><strong>8. Attack services and exploit kits arise for mobile (and other) platforms.<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28536\"><span id=\"yui_3_16_0_1_1421281345919_28535\">The last few years of cybercrime have been hallmarked by the rise of products and services to make hacking and exploitation point-and-click easy. With mobile platforms being so popular (and increasingly holding juicy data) we will see more crime packs and tools focusing on these devices explicitly. We may also see this trend come to fruition for other platforms in the IoT space as these devices proliferate around us.<\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28537\"><strong>\u00a0<\/strong><\/div>\n<div><strong>9. The gap between Industrial Control Systems and real world security only grows bigger.<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28539\"><span id=\"yui_3_16_0_1_1421281345919_28538\">Industrial Control Systems (ICS) are typically 10 years or more behind the mainstream in terms of security. Over the next couple of years we anticipate more serious flaws exposed and used by attackers as opportunities vacillate between state-sponsored attacks and financially motivated ones. In short, it is an area of significant risk.<\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28540\"><strong>\u00a0<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28541\"><strong>10. Interesting rootkit and bot capabilities may turn up new attack vectors.<\/strong><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28543\"><span id=\"yui_3_16_0_1_1421281345919_28542\">The technology industry is in the process of changing major platforms and protocols from those that we have relied on for some time, and these lower level changes will expose interesting flaws that cybercriminals may be able to capitalize on. This mass of major changes away from old guard technology standards could re-open old wounds and reveal major new security flaw categories.<\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28544\"><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28545\"><b>Connect with Sophos<\/b><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_13693\"><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_13692\" lang=\"DE\"><a id=\"yiv1194643178yui_3_16_0_1_1421361866845_13691\" href=\"http:\/\/soph.so\/CfuKd\" target=\"_blank\" rel=\"nofollow\"><span id=\"yiv1194643178yui_3_16_0_1_1421361866845_13690\" lang=\"EN-US\">Twitter<\/span><\/a><\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28556\"><span lang=\"DE\"><a href=\"http:\/\/soph.so\/Cfv36\" target=\"_blank\" rel=\"nofollow\"><span lang=\"EN-US\">LinkedIn<\/span><\/a><\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28555\"><span lang=\"DE\"><a href=\"http:\/\/soph.so\/CfvaA\" target=\"_blank\" rel=\"nofollow\"><span lang=\"EN-US\">Facebook<\/span><\/a><\/span><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_13694\"><span lang=\"DE\"><a href=\"https:\/\/plus.google.com\/+sophos\" target=\"_blank\" rel=\"nofollow\"><span lang=\"EN-US\">Google+<\/span><\/a><\/span><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_13695\"><span lang=\"DE\"><a href=\"http:\/\/soph.so\/Cgbwa%20\" target=\"_blank\" rel=\"nofollow\"><span lang=\"EN-US\">Spiceworks<\/span><\/a><\/span><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_13696\"><span lang=\"DE\"><a href=\"http:\/\/www.youtube.com\/user\/sophoslabs\" target=\"_blank\" rel=\"nofollow\"><span lang=\"EN-US\">YouTube<\/span><\/a><\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28554\"><span lang=\"DE\"><a href=\"http:\/\/blogs.sophos.com\/\" target=\"_blank\" rel=\"nofollow\"><span lang=\"EN-US\">Sophos Blog<\/span><\/a><\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28553\"><span lang=\"DE\"><a href=\"http:\/\/nakedsecurity.sophos.com\/\" target=\"_blank\" rel=\"nofollow\"><span lang=\"EN-US\">Naked Security News<\/span><\/a><\/span><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28552\"><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_13697\"><b>About Sophos<\/b><\/div>\n<div id=\"yiv1194643178yui_3_16_0_1_1421361866845_13698\">More than 100 million users in 150 countries rely on Sophos\u2019 complete security solutions as the best protection against complex threats and data loss. Simple to deploy, manage, and use, Sophos\u2019 award-winning encryption, endpoint security, web, email, mobile and network security solutions are backed by SophosLabs &#8211; a global network of threat intelligence centers.<\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28551\"><\/div>\n<div id=\"yui_3_16_0_1_1421281345919_28550\">Sophos is headquartered in Oxford, UK. More information is available at <a href=\"http:\/\/www.sophos.com\/\" target=\"_blank\" rel=\"nofollow\">www.sophos.com<\/a>.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MANILA, Philippines \u2013 December 17, 2014 \u2013Sophos today released the Security Threat Trends 2015 report that exposes the biggest security risks on the horizon and explains the real-world impact of evolving cyber threats on businesses and consumers in the New Year. After a year of big data breaches like Home Depot and Sony, it\u2019s easy&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-532","post","type-post","status-publish","format-standard","hentry","category-techbeatcast"],"_links":{"self":[{"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/posts\/532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/comments?post=532"}],"version-history":[{"count":1,"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/posts\/532\/revisions"}],"predecessor-version":[{"id":535,"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/posts\/532\/revisions\/535"}],"wp:attachment":[{"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/media?parent=532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/categories?post=532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.techbeatph.com\/wproot\/wp-json\/wp\/v2\/tags?post=532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}