By PJ Kirner, CTO & Founder of Illumio
1) “We’ll start to hear more about the convergence of physical infiltration with cyberattacks, challenging security across the board.”
“Cyberattacks on an enterprise or a government can be carried out remotely but, in 2019, we started hearing more about the physical element added to the mix. Just look at the woman who had a thumb drive loaded with malware that got into Mar-a-Lago. Although she wasn’t able to successfully tap into the network, she still had a convincing enough story to get past physical checkpoints manned by the Secret Service.
And it doesn’t take sophisticated software or intelligence operations to execute these attacks – a well-planned, staged scenario is all it takes. For instance, someone could pose as an electrician to gain physical access to a hospital being built, walking around unimpeded until they find an unprotected device to access the network. I believe we’ll see more of these high-profile, hybrid cyber-physical attacks in 2020.”
2) “AI and speech technology will be exploited, making voice a new weapon of choice.”
“If there’s one thing that malicious actors are good at, it’s creativity. We’ll see business email compromise (BEC) extend further over into voice next year. Even though many organizations have educated employees on how to spot potential phishing emails, many aren’t ready for voice to do the same as they’re very believable and there really aren’t many effective, mainstream ways of detecting them. And while these types of “voishing” attacks aren’t new, we’ll see more malicious actors leveraging influential voices to execute attacks next year.
And it’s not as hard as it sounds – it’s easier than ever to get an audio clip of an executive, CEO, or world leader giving a speech and then altering it for nefarious purposes. Imagine receiving an urgent call or voicemail from your “boss”, asking to share credentials for a secure platform or system. Without any packaged-up, off-the-shelf solutions to help detect these threats, we’re going to see a lot more voice-related attacks in 2020 that will be harder to identify and even harder to protect against.”
3) “Our sons and daughters will quickly become a new threat vector to enterprise security.”
“Almost everyone has a smart, connected device these days and kids are no exception. If they don’t have their own, they’ll probably just grab their parents’ phone or tablet to play games or watch TV – often unsupervised. As digital natives, technology is second nature to them but they’re not thinking about cybersecurity at all, which is why they’ll become prime targets.
Unfortunately, no one is off-limits when it comes to cybersecurity threats and our kids will be squarely in the crosshairs next year. Whether it’s the child of an executive, an executive assistant, or even someone with administrative privileges, it only takes one wrong click for them to implant malware on their parent’s phone, opening up the back door for a bad actor to get into the company network. This will become much more prevalent in 2020.”
About the Author
As Chief Technology Officer and founder, PJ is responsible for Illumio’s technology vision and platform architecture. PJ has 20 years of experience in engineering, with a focus on addressing the complexities of data centers. Prior to Illumio, PJ was CTO at Cymtec. He also held several roles at Juniper Networks, including distinguished engineers focused on advancing Juniper’s network security and layer 4-7 services plane. PJ graduated with honors from Cornell University.