Cyber-attacks have dominated the headlines in the past decade; wreaking havoc with systems, holding data to ransom, undermining public trust in corporations and governments, and causing untold financial damage.
As security and business leaders prepare for a new year, let’s take a look at the top five cybersecurity threats and priorities they will likely face.
1. Election security will take center stage
If 2016 was a proof of concept for how elections can be manipulated, 2020 will prove to be an open season for hackers. However, the game will be different. Moving beyond disinformation and influence campaigns, nation-state threat actors have their eye on a bigger prize – our vulnerable election infrastructure. And they’re already busy testing their tools.
Just this past week, Ohio’s Secretary of State announced that during the November elections a Russian organization attempted to probe the state’s election website looking for potential vulnerabilities.
Meanwhile, in Pennsylvania, a bug in a touchscreen voting system caused votes cast in a Northampton County judge’s race to be manipulated. Voters complained that votes that should have gone to the Democrat candidate were switched to the Republican candidate, only reverting after a system reset. Although no evidence of cyber foul play was detected, the incident underscores the vulnerabilities and weak security performance inherent in U.S. election systems.
2. Retail POS systems are waiting to be breached
Online and in-store digital point-of-sale (POS) systems have long been a target for cyber criminals. Come 2020, retailers will continue to be overrun with organized cyber criminals looking to sell credit card data on the dark web.
Today, roughly a quarter of all data breaches in the retail sector occur as a result of vulnerabilities in POS systems. Most of the time, these incidents are entirely preventable. Basic cybersecurity hygiene practices such as patching and updating systems can prevent most attacks. However, implementing these solutions can be a time-consuming and costly process that often involves taking the systems offline, which is not an option for busy retailers and their customers. Furthermore, most retail IT teams operate on a shoestring budget that prioritizes website performance and user experience over software and hardware updates.
Faced with these challenges, many retailers choose to outsource their POS systems to a third-party, reducing the burden on IT. Yet this introduces third-party risk into the equation. Bitsight data shows that 60-70% of POS breaches involve a third-party.
But the threat doesn’t stop there. Fourth parties and n-th parties deserve attention as well. The trouble is, companies often aren’t sure how to adequately monitor these fourth parties, so they end up feeling “blind” in the relationship. It may no longer suffice to simply add language in a vendor contract that asserts that everything that applies to a third-party vendor also applies to the vendor’s subcontractors.
As the new year approaches, it’s contingent on retailers to prioritize their POS providers as a critical third-party and move towards continuously monitoring their performance and that of their fourth and nth parties in order to mitigate any risk flowing up to their own organizations.
3. Oil, gas, healthcare, and utilities remain prime targets
2020 will not be kind to the oil, gas, utilities and healthcare sectors, each of which is a lucrative target for threat actors and cyber warfare mongers. Based on past performance and the motives of threat actors, a rise in the number of attacks against critical U.S. infrastructure and healthcare organizations is inevitable.