Global cyber crime costs are expected to increase by nearly 15 per cent on a yearly basis over the next four years to reach $10.5 trillion annually by 2025, from $3tn in 2015, California research company Cybersecurity Ventures has said.
Cyber criminals have taken note of successful tactics from this year, including those making headlines tied to ransomware, nation states, social media and the shifting reliance on a remote workforce.
Industry experts expect them to pivot those into next year's campaigns and grow in sophistication, wielding the potential to wreak more havoc across industries.
“Over this past year, we have seen cyber criminals get smarter and quicker at retooling their tactics to follow new bad actor schemes – from ransomware to nation states – and we don’t anticipate that changing in 2022,” Raj Samani, fellow and chief scientist of the combined company formed after the merger of McAfee Enterprise and FireEye, said.
“With the evolving threat landscape and continued impact of the global pandemic, it is crucial that enterprises stay aware of the cyber security trends so that they can be proactive and actionable in protecting their information,” Mr Samani said.
The National looks at the top 10 cyber security trends of the year ahead:
Weaponising operational technology environments
Cyber criminals could weaponise operational technology environments to harm or kill humans in the next four years, the Connecticut-based technology research and consulting company Gartner has said.
The OT is a type of computing and communication system – including both hardware and software – that controls industrial operations, mainly focusing on the physical devices and processes they use. It is used to gather and analyse data in real time, which is further used to monitor a manufacturing unit or to control equipment.
Various industries, such as telecoms and oil and gas, use OTs to ensure different devices work in co-ordination.
Attacks on OT environments have evolved from “immediate process disruption” such as shutting down a plant – for example in the recent Colonial Pipeline ransomware attack that took down the largest fuel pipeline in the US – to compromising the “integrity of industrial environments” with intent to cause physical or reputational harm, Gartner said.
Remote working brings new challenges
Remote working spurred by the Covid-19 pandemic could compound cyber threats in 2022.
Home devices that employees use to access office networks are usually not subject to the same security restrictions as corporate devices. This complicates efforts to control and monitor employees’ digital behaviour, applications and data outside traditional firewalls, industry analysts said.
Geopolitical cyber concerns pose growing risks
Some state actors will launch cyber attacks because they are “cheap, reliable, portable, easily hidden and hard to detect”, Moody’s Investors Service said in a report earlier this year.
The state-sponsored attacks threaten reputational damage, cause disruption of work flow and loss of intellectual property.
“Entities that find themselves the targets of these attacks could experience substantial credit damage,” the rating agency had said at the time.
Use of social media for attacks
While using social media to target victims is not a new strategy, it is relatively uncommon. It demands a level of research to engage the vulnerable target into interactions and establish fake profiles.
“The targeting of individuals has proven a very successful channel and we predict the use of this vector could grow not only through espionage groups, but [also] other threat actors looking to infiltrate organisations for their own criminal gain,” McAfee Enterprise and FireEye said in its cyber threats predictions for 2022.
Cryptocurrency exchanges to experience an increase in attacks
Cryptocurrency exchanges experienced a 10-fold increase in attacks in the first half of the year compared with the prior year period, said a report by cyber threat intelligence company PhishLabs, although it did not disclose the exact number of attacks.
The majority of the cryptocurrency attacks were orchestrated through social media.
“We anticipate cryptocurrency businesses will continue to be aggressively targeted by threat actors through social media in future … [it is] due to a majority of their activity and communication taking place through social platforms,” the report said.
Hackers pulled off the biggest cryptocurrency heist yet on August 10, stealing $613 million in digital coins from token-swapping platform Poly Network, only to return $260m worth of tokens less than 24 hours later.
Phishing attacks
Phishing typically comes in the form of fraudulent emails or pop-up messages that aim to obtain personal information from victims, such as credit card details and sensitive data, including personal identification numbers, usernames and passwords.
Phishing emails may also secretly install malicious software or malware in victims' computers. Such nefarious installations may be a virus or spyware designed to collect more information, which could lead to further fraud.
API becoming a lucrative target
Internet of Things and 5G traffic between API (application programming interface) services and apps will make them increasingly lucrative targets, causing unwanted exposure of information.
The connected nature of APIs potentially also introduces additional risks to businesses as they become an entry vector for wider supply chain attacks, McAfee Enterprise and FireEye said.
“In most cases, attacks targeting APIs go undetected as they are generally considered as trusted paths and lack the same level of governance and security controls.”
Cyber security talent crunch
The coming year will prove to be the most challenging one yet with regards to the continuing cyber security talent crunch, said the US cyber security firm BeyondTrust.
“Some drivers of this supply-demand imbalance include the accelerated adoption of hybrid cloud and digital transformation initiatives, post-pandemic projects ramping up and budgets becoming available for spend,” it added.
Rise of ransomware
The use of ransomware has picked up pace and became more dangerous in 2021. It will continue its rapid rise next year and its variations will increase with the frequency of attacks.
“Organisations must stop trying to prevent adversaries’ missions and instead prevent them from being worthwhile,” said Marty Edwards, vice president of operational technology at Columbia-headquartered cyber security company Tenable.
“In other words, organisations must make sure these missions cost too much to conduct. If the reward doesn’t cover the cost of the investment, threat actors won’t pursue it,” he added.
Cloud migration poses threat
Nearly half of the organisations moved business-critical functions to the cloud as a direct result of the pandemic, said Tenable.
However, cloud migration requires specific considerations that will likely be overlooked in 2022. For instance, detecting and preventing malicious activity in the cloud is a lot different, said Bob Huber, chief security officer at Tenable.
“And this can be further complicated by the nuances of working with cloud providers, as well as other company stakeholders looking to rapidly adopt new services in the cloud.
“Unless organisations educate their entire teams, not just security teams, about securing the cloud, they will inevitably pay the price as their migration accelerates,” said Mr Huber.
In numbers: China in Dubai
The number of Chinese people living in Dubai: An estimated 200,000
Number of Chinese people in International City: Almost 50,000
Daily visitors to Dragon Mart in 2018/19: 120,000
Daily visitors to Dragon Mart in 2010: 20,000
Percentage increase in visitors in eight years: 500 per cent
Babumoshai Bandookbaaz
Director: Kushan Nandy
Starring: Nawazuddin Siddiqui, Bidita Bag, Jatin Goswami
Three stars
How to apply for a drone permit
- Individuals must register on UAE Drone app or website using their UAE Pass
- Add all their personal details, including name, nationality, passport number, Emiratis ID, email and phone number
- Upload the training certificate from a centre accredited by the GCAA
- Submit their request
What are the regulations?
- Fly it within visual line of sight
- Never over populated areas
- Ensure maximum flying height of 400 feet (122 metres) above ground level is not crossed
- Users must avoid flying over restricted areas listed on the UAE Drone app
- Only fly the drone during the day, and never at night
- Should have a live feed of the drone flight
- Drones must weigh 5 kg or less
The specs
Engine: 2.0-litre 4cyl turbo
Power: 261hp at 5,500rpm
Torque: 405Nm at 1,750-3,500rpm
Transmission: 9-speed auto
Fuel consumption: 6.9L/100km
On sale: Now
Price: From Dh117,059
Sri Lanka's T20I squad
Thisara Perera (captain), Dilshan Munaweera, Danushka Gunathilaka, Sadeera Samarawickrama, Ashan Priyanjan, Mahela Udawatte, Dasun Shanaka, Sachith Pathirana, Vikum Sanjaya, Lahiru Gamage, Seekkuge Prasanna, Vishwa Fernando, Isuru Udana, Jeffrey Vandersay and Chathuranga de Silva.
You might also like to read
Sanju
Produced: Vidhu Vinod Chopra, Rajkumar Hirani
Director: Rajkumar Hirani
Cast: Ranbir Kapoor, Vicky Kaushal, Paresh Rawal, Anushka Sharma, Manish’s Koirala, Dia Mirza, Sonam Kapoor, Jim Sarbh, Boman Irani
Rating: 3.5 stars
About Krews
Founder: Ahmed Al Qubaisi
Based: Abu Dhabi
Founded: January 2019
Number of employees: 10
Sector: Technology/Social media
Funding to date: Estimated $300,000 from Hub71 in-kind support
In-demand jobs and monthly salaries
- Technology expert in robotics and automation: Dh20,000 to Dh40,000
- Energy engineer: Dh25,000 to Dh30,000
- Production engineer: Dh30,000 to Dh40,000
- Data-driven supply chain management professional: Dh30,000 to Dh50,000
- HR leader: Dh40,000 to Dh60,000
- Engineering leader: Dh30,000 to Dh55,000
- Project manager: Dh55,000 to Dh65,000
- Senior reservoir engineer: Dh40,000 to Dh55,000
- Senior drilling engineer: Dh38,000 to Dh46,000
- Senior process engineer: Dh28,000 to Dh38,000
- Senior maintenance engineer: Dh22,000 to Dh34,000
- Field engineer: Dh6,500 to Dh7,500
- Field supervisor: Dh9,000 to Dh12,000
- Field operator: Dh5,000 to Dh7,000
NEW%20PRICING%20SCHEME%20FOR%20APPLE%20MUSIC%2C%20TV%2B%20AND%20ONE
%3Cp%3E%3Cstrong%3EApple%20Music%3Cbr%3EMonthly%20individual%3A%20%3C%2Fstrong%3E%2410.99%20(from%20%249.99)%3Cstrong%3E%3Cbr%3EMonthly%20family%3A%20%3C%2Fstrong%3E%2416.99%20(from%20%2414.99)%3Cstrong%3E%3Cbr%3EIndividual%20annual%3A%20%3C%2Fstrong%3E%24109%20(from%20%2499)%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EApple%20TV%2B%3Cbr%3EMonthly%3A%20%3C%2Fstrong%3E%246.99%20(from%20%244.99)%3Cstrong%3E%3Cbr%3EAnnual%3A%20%3C%2Fstrong%3E%2469%20(from%20%2449.99)%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EApple%20One%3Cbr%3EMonthly%20individual%3A%20%3C%2Fstrong%3E%2416.95%20(from%20%2414.95)%3Cstrong%3E%3Cbr%3EMonthly%20family%3A%20%3C%2Fstrong%3E%2422.95%20(from%20%2419.95)%3Cstrong%3E%3Cbr%3EMonthly%20premier%3A%20%3C%2Fstrong%3E%2432.95%20(from%20%2429.95)%3C%2Fp%3E%0A
Moon Music
Artist: Coldplay
Label: Parlophone/Atlantic
Number of tracks: 10
Rating: 3/5
MATCH INFO
League Cup, last 16
Manchester City v Southampton, Tuesday, 11.45pm (UAE)
Champion%20v%20Champion%20(PFL%20v%20Bellator)
%3Cp%3EHeavyweight%3A%20Renan%20Ferreira%20v%20Ryan%20Bader%20%3Cbr%3EMiddleweight%3A%20Impa%20Kasanganay%20v%20Johnny%20Eblen%3Cbr%3EFeatherweight%3A%20Jesus%20Pinedo%20v%20Patricio%20Pitbull%3Cbr%3ECatchweight%3A%20Ray%20Cooper%20III%20v%20Jason%20Jackson%3Cbr%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EShowcase%20Bouts%3C%2Fstrong%3E%3Cbr%3EHeavyweight%3A%20Bruno%20Cappelozza%20(former%20PFL%20World%20champ)%20v%20Vadim%20Nemkov%20(former%20Bellator%20champ)%3Cbr%3ELight%20Heavyweight%3A%20Thiago%20Santos%20(PFL%20title%20contender)%20v%20Yoel%20Romero%20(Bellator%20title%20contender)%3Cbr%3ELightweight%3A%20Clay%20Collard%20(PFL%20title%20contender)%20v%20AJ%20McKee%20(former%20Bellator%20champ)%3Cbr%3EFeatherweight%3A%20Gabriel%20Braga%20(PFL%20title%20contender)%20v%20Aaron%20Pico%20(Bellator%20title%20contender)%3Cbr%3ELightweight%3A%20Biaggio%20Ali%20Walsh%20(pro%20debut)%20v%20Emmanuel%20Palacios%20(pro%20debut)%3Cbr%3EWomen%E2%80%99s%20Lightweight%3A%20Claressa%20Shields%20v%20Kelsey%20DeSantis%3Cbr%3EFeatherweight%3A%20Abdullah%20Al%20Qahtani%20v%20Edukondal%20Rao%3Cbr%3EAmateur%20Flyweight%3A%20Malik%20Basahel%20v%20Vinicius%20Pereira%3C%2Fp%3E%0A
MATCH INFO
Tottenham 4 (Alli 51', Kane 50', 77'. Aurier 73')
Olympiakos 2 (El-Arabi 06', Semedo')
THE DETAILS
Deadpool 2
Dir: David Leitch
Starring: Ryan Reynolds, Josh Brolin, Justin Dennison, Zazie Beetz
Four stars
Manchester City transfers:
OUTS
Pablo Zabaleta, Bacary Sagna, Gael Clichy, Willy Caballero and Jesus Navas (all released)
INS
Ederson (Benfica) £34.7m, Bernardo Silva (Monaco) £43m
ON THEIR WAY OUT?
Joe Hart, Eliaquim Mangala, Samir Nasri, Wilfried Bony, Fabian Delph, Nolito and Kelechi Iheanacho
ON THEIR WAY IN?
Dani Alves (Juventus), Alexis Sanchez (Arsenal)
Stamp%20duty%20timeline
%3Cp%3E%3Cstrong%3EDecember%202014%3A%3C%2Fstrong%3E%20%20Former%20UK%20chancellor%20of%20the%20Exchequer%20George%20Osborne%20reforms%20stamp%20duty%20land%20tax%20(SDLT)%2C%20replacing%20the%20slab%20system%20with%20a%20blended%20rate%20scheme%2C%20with%20the%20top%20rate%20increasing%20to%2012%20per%20cent%20from%2010%20per%20cent%3A%3C%2Fp%3E%0A%3Cp%3EUp%20to%20%C2%A3125%2C000%20%E2%80%93%200%25%3B%20%C2%A3125%2C000%20to%20%C2%A3250%2C000%20%E2%80%93%202%25%3B%20%C2%A3250%2C000%20to%20%C2%A3925%2C000%20%E2%80%93%205%25%3B%20%C2%A3925%2C000%20to%20%C2%A31.5m%3A%2010%25%3B%20More%20than%20%C2%A31.5m%20%E2%80%93%2012%25%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EApril%202016%3A%3C%2Fstrong%3E%20New%203%25%20surcharge%20applied%20to%20any%20buy-to-let%20properties%20or%20additional%20homes%20purchased.%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EJuly%202020%3A%3C%2Fstrong%3E%20Chancellor%20Rishi%20Sunak%20unveils%20SDLT%20holiday%2C%20with%20no%20tax%20to%20pay%20on%20the%20first%20%C2%A3500%2C000%2C%20with%20buyers%20saving%20up%20to%20%C2%A315%2C000.%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EMarch%202021%3A%3C%2Fstrong%3E%20Mr%20Sunak%20extends%20the%20SDLT%20holiday%20at%20his%20March%203%20budget%20until%20the%20end%20of%20June.%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EApril%202021%3A%3C%2Fstrong%3E%202%25%20SDLT%20surcharge%20added%20to%20property%20transactions%20made%20by%20overseas%20buyers.%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EJune%202021%3A%3C%2Fstrong%3E%20SDLT%20holiday%20on%20transactions%20up%20to%20%C2%A3500%2C000%20expires%20on%20June%2030.%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EJuly%202021%3A%3C%2Fstrong%3E%20Tax%20break%20on%20transactions%20between%20%C2%A3125%2C000%20to%20%C2%A3250%2C000%20starts%20on%20July%201%20and%20runs%20until%20September%2030.%3C%2Fp%3E%0A
Getting%20there%20
%3Cp%3E%3Ca%20href%3D%22https%3A%2F%2Fwww.thenationalnews.com%2Ftravel%2F2023%2F01%2F12%2Fwhat-does-it-take-to-be-cabin-crew-at-one-of-the-worlds-best-airlines-in-2023%2F%22%20target%3D%22_self%22%3EEtihad%20Airways%20%3C%2Fa%3Eflies%20daily%20to%20the%20Maldives%20from%20Abu%20Dhabi.%20The%20journey%20takes%20four%20hours%20and%20return%20fares%20start%20from%20Dh3%2C995.%20Opt%20for%20the%203am%20flight%20and%20you%E2%80%99ll%20land%20at%206am%2C%20giving%20you%20the%20entire%20day%20to%20adjust%20to%20island%20time.%20%C2%A0%3C%2Fp%3E%0A%3Cp%3ERound%20trip%20speedboat%20transfers%20to%20the%20resort%20are%20bookable%20via%20Anantara%20and%20cost%20%24265%20per%20person.%20%C2%A0%3C%2Fp%3E%0A