The Top 10 New Emerging Cybersecurity Threats
Just as your organization thinks it is prepared, new cybersecurity threats appear. In March 2023, the European Union Agency for Cybersecurity (ENISA) published its list of the 10 top cybersecurity threats to emerge by 2030.
Based on an eight-month foresight exercise, the threats identified are still relevant today, but will have shifted in character, prompting ENISA to declare that the cybersecurity community must “…take all measures possible upfront to ensure we increase our resilience…”
Ranked in order, below are some of the most alarming threats identified by ENISA, plus suggested remediation actions your organization can take to ensure cyber resilience:
1. Supply Chain Compromise
The software supply chain is already the weakest link in most organizations’ networks—and the threat is expected to get much worse in the coming years.
As the market demands quicker software release cycles, ENISA predicts that software developers will reuse code and rely more heavily on open-source code libraries. Many of these components will not be scanned for vulnerabilities, creating more opportunities for malicious actors to compromise the supply chain. Transparency into the supply chain is essential to mitigating software supply chain attacks, but it will require more than traditional vendor security assessments.
To mitigate this threat:
Instead, your organization must continuously monitor the supply chain for emerging risk—during onboarding and for the duration of a vendor contract. Read more about how Bitsight ensures unprecedented visibility into supply chain risk.
2. Advanced disinformation campaigns
In 2030, nation states and non-state actors will expand their disinformation capabilities to manipulate communities using advanced artificial intelligence (AI) techniques to propagate deepfake attacks. In deepfake attacks, threat actors impersonate their targets, such as political rivals or corporate executives, to spread targeted messages, videos, and comments and influence public opinion.
A variety of methods can be used to propagate these attacks, including fraud, identity theft, unauthorized access, session hijacking, abuse of personal data, and more.
To mitigate this threat:
- Develop a plan to expand end-user awareness of deepfake technology and exploits through training and security awareness.
- Incorporate security performance management into your security program to better understand employee behavior that might contribute to the increased risk of a deepfake attack.
Read more about how to protect your organization from the emerging deepfake threat.
3. Rise of digital surveillance authoritarianism & loss of privacy
By 2030, governments and law enforcement agencies will collect vast amounts of personal data, including biometrics and digital identity information. In turn, these data troves will be targeted by nefarious hackers to steal identities, hack digital systems, and steal intellectual property.
Typical methods for perpetrating these attacks include malware, man-in-the-middle attacks, and more.
To mitigate this threat:
- Verify identities and prevent unauthorized access to devices and systems with multi-factor authentication and biometrics.
- As your attack surface expands—to the cloud, across remote networks, and mobile devices—ensure you have visibility into each digital asset, its security status, and areas of disproportionate risk so that you can prioritize remediation of vulnerabilities, such as unpatched software.
- Enforce mobile application protection to protect against credential theft, cloned apps, IP theft, and more.